ScarCruft Launches Multiplatform Supply-Chain Attack: Yanbian Gaming Platform Trojanized with BirdCall Backdoor

In late 2024, researchers uncovered a sophisticated supply-chain attack orchestrated by ScarCruft (APT37/Reaper), a North Korea-aligned advanced persistent threat (APT) group. This campaign targeted the Yanbian region in China, a sensitive area due to its ethnic Korean population and proximity to North Korea. The attack compromised both Windows and Android components of a Yanbian-themed gaming platform, embedding a powerful surveillance backdoor known as BirdCall. This case highlights the evolving tactics of ScarCruft and the growing risks posed by supply-chain compromises in consumer-facing platforms.

Yanbian Red Ten game

ScarCruft Profile

ScarCruft has operated since at least 2012, focusing on espionage against South Korea and other Asian nations. Its targets often include government agencies, military organizations, and industries of strategic interest to North Korea. Notably, ScarCruft has a history of targeting North Korean defectors, aligning with Pyongyang’s intelligence priorities. The Yanbian campaign fits this pattern, as the region hosts refugees and defectors who are of high interest to the regime.

Download page leading to trojanized games

BirdCall Backdoor: Windows and Android Variants

Windows BirdCall

First identified in 2021, BirdCall is a C++ backdoor with extensive spying capabilities. It can:

  • Capture screenshots and keystrokes
  • Steal credentials and files
  • Execute shell commands

For command-and-control (C&C), BirdCall leverages legitimate cloud services like Dropbox and pCloud, making detection more difficult. Its deployment typically involves a multistage loading chain with encrypted components, reflecting ScarCruft’s technical sophistication.

Android BirdCall

The Android variant, discovered in trojanized Yanbian games, mirrors many of the Windows backdoor’s capabilities. It collects contacts, SMS messages, call logs, documents, and media files, while also enabling screenshots and audio recordings. Researchers identified seven versions of Android BirdCall, showing active development between October 2024 and June 2025. This evolution underscores ScarCruft’s commitment to expanding its surveillance toolkit across platforms.

Discovery and Supply-Chain Compromise

The attack was uncovered when a malicious APK surfaced on VirusTotal. Analysis revealed it was a trojanized version of the Yanbian card game 延边红十 (Yanbian Red Ten), hosted on the official sqgame[.]net platform. Another game, 新画图 (New Drawing), was similarly compromised. Interestingly, while the Android and Windows clients were infected, the iOS version remained clean—likely due to Apple’s stricter app review process.

ESET telemetry later revealed that ScarCruft had also compromised the Windows desktop client via a trojanized mono.dll library, active since November 2024. This demonstrates ScarCruft’s ability to infiltrate multiple platforms within a single ecosystem.

Victimology

The primary targets appear to be ethnic Koreans in Yanbian, particularly refugees and defectors. By embedding malware in culturally relevant games, ScarCruft ensured high adoption rates among its intended victims. This strategy reflects a calculated approach: exploiting trusted community platforms to harvest sensitive personal and political information.

Attack Mechanics

The Android BirdCall backdoor was configured to:

  • Collect device identifiers, geolocation, and system information
  • Periodically exfiltrate files of interest (.doc, .pdf, .jpg, .p12, etc.)
  • Record audio during specific time windows (7–10 pm)
  • Communicate with C&C servers via Zoho WorkDrive

The backdoor’s stealth mechanisms included silent audio playback to prevent app suspension and update mechanisms to load newer versions without detection. These features highlight ScarCruft’s emphasis on persistence and covert surveillance.

Conclusion

ScarCruft’s Yanbian campaign demonstrates the group’s ability to weaponize supply-chain attacks against culturally specific platforms. By trojanizing games popular among ethnic Koreans, ScarCruft expanded its surveillance reach into refugee and defector communities. The discovery of Android BirdCall marks a significant evolution in ScarCruft’s arsenal, reinforcing the need for heightened vigilance in monitoring consumer-facing platforms.

Our Opinion

This case illustrates the dangerous intersection of geopolitics and cybersecurity. ScarCruft’s targeting of Yanbian is not random—it reflects North Korea’s strategic interest in monitoring defectors and refugees. By embedding malware in culturally relevant games, the group exploited trust and familiarity, turning leisure activities into surveillance tools. From a technical perspective, the campaign underscores the growing threat of supply-chain compromises, where attackers infiltrate legitimate platforms rather than relying solely on phishing or direct exploitation.

In our view, this attack highlights two critical lessons. First, organizations—even small gaming platforms—must adopt rigorous security practices, including code integrity checks and supply-chain monitoring. Second, the international community must recognize that cyber operations are increasingly being used as instruments of state power, targeting vulnerable populations for intelligence purposes. The Yanbian case is a stark reminder that cybersecurity is not just about protecting data—it is about safeguarding human lives and freedoms.