Proprietary ·

sqgame downloads delivered BirdCall

ScarCruft compromised sqgame downloads for Yanbian-themed games. Android APKs carried BirdCall, while a Windows update package led to RokRAT and BirdCall.

ESET found sqgame through a suspicious Android APK on VirusTotal. The file was a trojanized Yanbian Red Ten game, and the same APK was available from sqgame's official website. A second Android game, New Drawing, carried the same backdoor.

ScarCruft appears to have compromised the website or web server, not the original source tree. The Android packages were repackaged with a new entry activity and service definitions for BirdCall, then arranged to start the original game after the implant initialized.

The Windows side used the desktop client's update path. ESET found a trojanized mono.dll library from dating/20240429.zip; the added downloader fetched shellcode, which carried RokRAT, and telemetry showed RokRAT later installing BirdCall.

The likely target was the Yanbian Korean community in China, including people of interest to North Korea. BirdCall collected contacts, SMS, call logs, files, screenshots, audio, and device metadata, using cloud services for command and control.

Appendix · Affected releases

sqybhs.apk android
ybht.apk android
dating/20240429.zip sqgame windows updater
  • ESET described a trojanized Windows update package served from sqgame alongside the Android APKs, but did not publish a precise version identifier.

References

  1. Rigged game: ScarCruft compromises gaming platform in supply-chain attackwelivesecurity.com
  2. ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windowsthehackernews.com
  3. ScarCruft Spreads BirdCall Malware via Regional Gaming Platforminfosecurity-magazine.com
  4. ScarCruft deploys BirdCall malware in China supply chain attackhelpnetsecurity.com
  5. APT37 Hacks Gaming Platform to Spread New BirdCall Android Spywarecyberinsider.com

Source record: proprietary/sqgame/meta.yaml