216.73.216.6

A rigged game: compromises gaming platform in a supply-chain attack

· Published 05/05/2026 10:23 · Modified 05/05/2026 10:36

Export JSON

Essential information

Published
05/05/2026 10:23
Modified
05/05/2026 10:36
Tags
2026-05-05 android trojan birdcall gaming platform compromise supply chain attack yanbian targeting
Related entities
9 observables, 1 intrusion sets (apt), 21 techniques (mitre), 2 malware, 9 others

Description

North Korea-aligned APT group ScarCruft executed a multiplatform supply-chain attack targeting ethnic Koreans in China's Yanbian region, an area significant for North Korean refugees and defectors. Since late 2024, the group compromised a video gaming platform dedicated to Yanbian-themed games, trojanizing both Windows and Android components with the backdoor. The Windows client received malicious updates leading to RokRAT and subsequently deployment, while Android games were directly trojanized. This marks the first discovery of Android , capable of comprehensive surveillance including data collection, screenshots, and voice recording. The campaign focuses on espionage against individuals of interest to the North Korean regime, particularly refugees and defectors.

External references