North Korean APT37 Compromises Gaming Platform in Supply Chain Attack Targeting Ethnic Korean Defectors
ESET Research on May 5 reported that
ScarCruft's supply-chain approach, exploiting sqgame[.]net rather than direct spearphishing, reflects deliberate targeting of infrastructure embedded in Yanbian's ethnic Korean diaspora. The Windows package's clean-library swap after staging RokRAT and BirdCall, and the Android variant's Zoho WorkDrive C2 routing, signal practiced OPSEC refined across prior campaigns, per ESET Research corroborated by secondary outlets. Sqgame's failure to remediate after ESET's December 2025 notification extends exposure the operators likely anticipated. Yanbian's cross-border business community may represent a more operationally valuable collection target than its defector population alone. South Korean NIS public attribution by 4 June 2026 is
4 sources
- North Korean hackers trojanize gaming platform to spy on ethnic Koreans in China -
Help Net Security - A rigged game: ScarCruft compromises gaming platform in a supply-chain attack -
ESET WeLiveSecurity - North Korea-aligned APT group ScarCruft compromises gaming platform in supply-chain espionage attack, ESET Research finds -
GlobeNewswire (ESET Research) - ScarCruft hackers push BirdCall Android malware via game platform -
BleepingComputer