Adversary Intelligence — 2026-05-05

North Korean APT37 Compromises Gaming Platform in Supply Chain Attack Targeting Ethnic Korean Defectors

ESET Research on May 5 reported that ScarCruft (APT37) compromised sqgame[.]net, a gaming platform for ethnic Koreans in China's Yanbian region, in a supply-chain attack active since at least November 2024. A trojanized Windows update package embedded a downloader in a patched mono.dll that staged RokRAT, installed BirdCall, and then swapped in a clean library to erase the artifact; the malicious package was inactive at time of publication. Two Android games on the platform were separately repackaged with an Android port of BirdCall, collecting contacts, call logs, SMS, and documents with C2 traffic routed to Zoho WorkDrive. ESET notified sqgame of the compromise in December 2025, received no reply, and the Android APKs remained live on the site at publication.

Analysis
ScarCruft's supply-chain approach, exploiting sqgame[.]net rather than direct spearphishing, reflects deliberate targeting of infrastructure embedded in Yanbian's ethnic Korean diaspora. The Windows package's clean-library swap after staging RokRAT and BirdCall, and the Android variant's Zoho WorkDrive C2 routing, signal practiced OPSEC refined across prior campaigns, per ESET Research corroborated by secondary outlets. Sqgame's failure to remediate after ESET's December 2025 notification extends exposure the operators likely anticipated. Yanbian's cross-border business community may represent a more operationally valuable collection target than its defector population alone. South Korean NIS public attribution by 4 June 2026 is unlikely, as Seoul has consistently declined to name Pyongyang for operations targeting diaspora in Chinese territory.
4 sources
  1. North Korean hackers trojanize gaming platform to spy on ethnic Koreans in China - Help Net Security
  2. A rigged game: ScarCruft compromises gaming platform in a supply-chain attack - ESET WeLiveSecurity
  3. North Korea-aligned APT group ScarCruft compromises gaming platform in supply-chain espionage attack, ESET Research finds - GlobeNewswire (ESET Research)
  4. ScarCruft hackers push BirdCall Android malware via game platform - BleepingComputer

View in full brief →

UNCLASSIFIED // OPEN SOURCE