ScarCruft Hacks SQGame Gaming Platform Release Malware
ScarCruft Hacks SQGame Gaming Platform Release BirdCall Malware Insert Android and Windows Systems
In modern times, the purchase of video games is usually done through platforms instead of traditional discs. There are many platforms that provide video game distribution services, each of which is often presented as secure in the use of the platform, but many are not immune to hacking or using monitoring vulnerabilities to release malware such as this news.
According to a report by the website, The Hacker News has mentioned the detection of a malware release campaign called BirdCall with the hacking of the video game distribution platform SQGame (sqgame [.] net), a popular platform used by Korean residents of the Sino-North Korean-Russian border region. This area can be called a security vulnerability and international relations, as it is often the area where Korean defectors flee the river to escape from North Korea. A research team from ESET, a popular anti-Virus software developer, predicted that the campaign It may be intended to mainly tackle defectors, human rights activists and university professors in the area.
The malware is not new in any way, but has been used by ScarCruft hackers from North Korea since 2024, during which time it will be used by old versions of BirdCall malware that focus primarily on attacks on Windows users, but in 2025, an Android version has been detected with video games for use on the Android operating system downloaded from the site.
The Android version of BirdCall malware uses Multi-Stage Infection with Ruby or Python scripts as the initiator of the embedded process. The malware is similar to other backdoor malware, such as the function of secretly saving the screen on the victim's machine, the Keystroke Logging feature, the data theft feature recorded on Clipboard, the data theft feature, and the feature for running Shell commands on the victim's machine. The types of data that can be stolen are abundant, whether it is SMS or Short messages. Message Service, Contacts List, Media Files, Screenshots, Document Files, Audio Files. In addition, the research team also found that the Android version of the malware was used as a well-known cloud service to be used as a control system or C2 (Command and Control), such as pCloud, Yandex Disk, and Zoho WorkDrive.
By the video game files that caused the malware, the research team revealed that it was listed as follows:
sqgame.com [.] cn / ybht.apk
sqgame.com [.] cn / sqybhs.apk
The video game file contains malware. The research team predicted that it would come from a Supply Chain Attack by hacking websites and shuffling APK files for video game installation into a version where hackers insert malware instead.
For the Windows version that has been experiencing outbreaks since c.2024 (d. In 2567), a different method is used by using a fake update package as a decoy. If the victim installs the update, it will embed the DLL file of the malware that acts as the next malware (Loader). This malware will check processes to make sure that no malware analysis is running and that it is not running in a Virtual Machine environment. If not detected, it will download and run the Shell code to install a remote control malware (RAT or Remote Access Trojan) named RokRAT. This malware acts to reinstall the Windows version of BirdCall malware.
# Trending # Lemon 8 Howtoo # lemon 8 diary # scarcruft # freedomhack






























































































