TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Help Net Security

North Korean hackers trojanize gaming platform to spy on ethnic Koreans in China

Sinisa Markovic · 1 day ago · Read original ↗

ATT&CK techniques detected

5 predictions
T1204.002Malicious File
78%
“delivered the rokrat backdoor, which then installed birdcall, a more capable c + + implant eset first attributed to scarcruft in 2021. after execution, the trojanized mono. dll is swapped back to a clean copy fetched from another compromised korean site, erasing the visible artif…”
T1071.001Web Protocols
78%
“. m. local time. command - and - control traffic runs over https to zoho workdrive accounts ; eset observed twelve such accounts, all registered with zohomail addresses. the implant also supports pcloud and yandex disk in code, neither of which was active during the investigation…”
T1204.002Malicious File
52%
“north korean hackers trojanize gaming platform to spy on ethnic koreans in china north korean hackers trojanize gaming platform to spy on ethnic koreans in china a gaming platform built for ethnic koreans in china has been serving backdoored windows and android software to its us…”
T1219Remote Access Tools
35%
“is a port of the windows birdcall backdoor and implements a subset of its commands. eset identified seven builds, ranging from version 1. 0 in october 2024 to version 2. 0 in june 2025. version 2. 0 adds code obfuscation. the backdoor collects contacts, call logs, sms messages, a…”
T1588.001Malware
31%
“north korean hackers trojanize gaming platform to spy on ethnic koreans in china north korean hackers trojanize gaming platform to spy on ethnic koreans in china a gaming platform built for ethnic koreans in china has been serving backdoored windows and android software to its us…”

Summary

A gaming platform built for ethnic Koreans in China has been serving backdoored Windows and Android software to its users since late 2024. The platform, sqgame[.]net, hosts traditional card and board games for a community that sits along the North Korean border and includes many refugees and defectors. ESET researchers tied the operation to ScarCruft, a North Korea-aligned espionage group also tracked as APT37 and Reaper, which has been active since at least 2012. How … More

The post North Korean hackers trojanize gaming platform to spy on ethnic Koreans in China appeared first on Help Net Security.