Wednesday, May 20, 2026
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

North Korea-aligned APT group ScarCruft compromises gaming platform in supply‑chain espionage attack, ESET Research finds

May 6, 2026
in Artificial Intelligence, GlobeNewswire, Web3
Reading Time: 6 mins read
5
SHARES
251
VIEWS
Share on TwitterShare on LinkedInShare on Facebook
  • North Korea-aligned APT group ScarCruft compromised a video game platform used by ethnic Koreans living in the Yanbian region of China.
  • The gaming platform’s Windows client was compromised through a malicious update leading to the RokRAT backdoor, which deployed the more sophisticated BirdCall backdoor.
  • Android games available on the gaming platform were trojanized to contain a new tool in ScarCruft’s arsenal – an Android version of the BirdCall backdoor.
  • The goal of the campaign is espionage, with the backdoor capable of collecting personal data and documents, taking screenshots, and making voice recordings.
  • It is probable that the attack was aimed at collecting information on individuals deemed of interest to the North Korean regime – most likely refugees or defectors.

BRATISLAVA, Slovakia, May 05, 2026 (GLOBE NEWSWIRE) — ESET researchers have uncovered a multiplatform supply-chain attack by North Korea-aligned APT group ScarCruft, targeting the Yanbian region in China – home to ethnic Koreans and a crossing point for North Korean refugees and defectors. In the attack, probably ongoing since late 2024, ScarCruft compromised Windows and Android components of a video game platform dedicated to Yanbian-themed games, trojanizing them with a backdoor. The backdoor, named BirdCall by ESET, was originally known to target Windows only; the Android version was later discovered as part of this supply-chain attack.

The Android version of BirdCall, discovered in the latest attack, implements a subset of the commands and capabilities of the Windows backdoor – it collects contacts, SMS messages, call logs, documents, media files, and private keys. It can also take screenshots and record surrounding audio. ESET discovered, based on this investigation, that Android BirdCall has been actively developed over a span of several months and at least seven versions have been deployed.

Since the website compromised in this attack is dedicated to the people of Yanbian and their traditional games, ESET concludes that the primary targets are ethnic Koreans living in Yanbian. It is probable that the attack was aimed at collecting information on individuals based in (or originating from) the Yanbian region and deemed of interest to the North Korean regime – most likely refugees or defectors.

The gaming platform’s Windows client was compromised through a malicious update leading to the RokRAT backdoor, which deployed the more sophisticated BirdCall backdoor. “Victims downloaded the trojanized games via a web browser from a single page on their devices and likely installed them intentionally. We did not identify any other APK locations or any malicious APKs on the official Google Play store. We were unable to determine when the website was first compromised and the supply-chain attack started. However, based on our analysis of the deployed malware, we estimate that it happened in late 2024,” says ESET researcher Filip Jurčacko, who discovered the latest attack by ScarCruft.

The Windows backdoor was initially discovered in 2021 and attributed to ScarCruft as part of ESET Threat Intelligence Reporting . The original Windows backdoor has a wide range of spying capabilities, including taking screenshots, logging keystrokes and clipboard content, stealing credentials and files, and executing shell commands. For C&C purposes, the backdoor utilizes legitimate cloud storage services, such as Dropbox or pCloud, or compromised websites.

ScarCruft, also known as APT37 or Reaper, has been operating since at least 2012 and is suspected to be a North Korean espionage group. It primarily focuses on South Korea, but other Asian countries have also been targeted. ScarCruft seems to be interested mainly in government and military organizations, and companies in various industries linked to the interests of North Korea. The group also targets North Korean defectors.

For a more details about BirdCall, check out the latest ESET Research blogpost “A rigged game: ScarCruft compromises gaming platform in a supply-chain attack,” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

About ESET

ESET® provides cutting-edge cybersecurity to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown— securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit http://www.eset.com or follow our social media, podcasts and blogs.

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.

ShareTweet1ShareSendShare2
Previous Post

Candescent Cares Donates $50,000 to Jump$tart Coalition for Personal Financial Literacy

Next Post

LECTRA: Implementation of a share buyback program

Related Posts

ThriveSparrow Advances Automated Employee Lifecycle Listening to Help Organizations Detect Attrition Risk Sooner

Automated lifecycle surveys, powered by AI-driven analytics, help HR leaders act before employee disengagement becomes costly. SAN FRANCISCO, CA / ACCESS Newswire / May 20, 2026 / ThriveSparrow, the AI-powered employee success platform, has strengthened its automated lifecycle listening framework to help organizations monitor employee experience from day-one onboarding to...

Read moreDetails

Moburst Secures $11.8M Investment from Chrysalis Holdings to Accelerate Digital Capabilities and Client Growth

NEW YORK, May 20, 2026 (GLOBE NEWSWIRE) -- Moburst, the global leader in digital marketing and AI-powered solutions, today announces a strategic $11.8 million investment from Chrysalis Holdings, LLC, a leading private investment firm. This financial backing will support Moburst’s growth and enhance the suite of services provided to NewDay...

Read moreDetails

FLYR Powers Riyadh Air’s Debut as World’s First Full-Service Airline Built for Modern Retailing

RIYADH, Saudi Arabia, May 20, 2026 (GLOBE NEWSWIRE) -- FLYR, the technology company leading the airline industry toward modern commerce, marks a historic milestone today as its partner, Riyadh Air, the world’s newest and only digitally-native airline, becomes the first full-service carrier to launch based exclusively on an Offer &...

Read moreDetails

&money reports 100% revenue growth, DKK 10M net profit, and targets 1M+ meetings in 2026

Switzerland,  20 May 2026 Trifork Group AG 
  Press Release  &money reports 100% revenue growth, DKK 10M net profit, and targets 1M+ meetings in 2026 
 
 &money, the Denmark-based advisory technology company founded by Trifork together with Nykredit, Spar Nord and Arbejdernes Landsbank (now AL Sydbank), today announced its 2025 results, reporting approximately 100% revenue...

Read moreDetails

WISeKey and SEALSQ Announce Roadmap and Launch of Official Website for WISeRobot.ch, Integrating Human-Centric AI With Post-Quantum Security in Robotics

WISeKey and SEALSQ Announce Roadmap and Launch of Official Website for WISeRobot.ch, Integrating Human-Centric AI With Post-Quantum Security in Robotics GENEVA, Switzerland — May 20, 2026 - WISeKey International Holding Ltd (NASDAQ: WKEY; SIX: WIHN) (“WISeKey” or the “Company”), a global leader in cybersecurity, digital identity and IoT, and its Semiconductors,...

Read moreDetails

SEALSQ and WISeKey Announce Roadmap and Launch of Official Website for WISeRobot.ch, Integrating Human-Centric AI With Post-Quantum Security in Robotics

Geneva, Switzerland, May 20, 2026 (GLOBE NEWSWIRE) -- SEALSQ Corp (NASDAQ: LAES) ("SEALSQ" or "Company"), a company that focuses on developing and selling Semiconductors, PKI, and Post-Quantum technology hardware and software products, and its parent company WISeKey International Holding Ltd (NASDAQ: WKEY; SIX: WIHN) (“WISeKey”), a global leader in cybersecurity,...

Read moreDetails

iPower Inc. Announces 1-for-8 Reverse Stock Split

RANCHO CUCAMONGA, Calif., May 19, 2026 (GLOBE NEWSWIRE) -- iPower Inc. (Nasdaq: IPW) (“iPower” or the “Company”), a technology- and data-driven supply chain and infrastructure provider for online retailers and brands, today announced that it will effect a 1-for-8 reverse stock split of its issued and outstanding common stock. The...

Read moreDetails

Crypto News Today: AlphaPepe Presale Stage 16 Nears Sell Out While Bitcoin Price Prediction Targets $250,000

MONACO, May 19, 2026 (GLOBE NEWSWIRE) -- Crypto news today is turning toward AlphaPepe after the project announced that Stage 16 is nearing sell-out while the presale continues at $0.01734 per token. The project has raised over $1.27 million, the holder count has passed 8,800, the AlphaSwap AI DEX demo...

Read moreDetails

DELLA Launches Memorial Day Sale With Up to 12% Off Energy-Efficient Cooling Solutions

LOS ANGELES, CA, May 19, 2026 (GLOBE NEWSWIRE) -- DELLA today launched its Memorial Day Sale, offering limited-time savings on eligible home cooling systems as homeowners prepare for warmer summer weather. From now through May 26, customers can save 10% on orders over $300, save 12% on orders over $2,000,...

Read moreDetails

DELLA Launches Memorial Day Sale With Up to 12% Off Energy-Efficient Cooling Solutions

LOS ANGELES, CA, May 19, 2026 (GLOBE NEWSWIRE) -- DELLA today launched its Memorial Day Sale, offering limited-time savings on eligible home cooling systems as homeowners prepare for warmer summer weather. From now through May 26, customers can save 10% on orders over $300, save 12% on orders over $2,000,...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • Top Cross-Chain DeFi Solutions to Watch by 2025

    101 shares
    Share 40 Tweet 25
  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    166 shares
    Share 66 Tweet 42
  • Understanding Soulbound Tokens SBT Their Definition and Significance

    58 shares
    Share 23 Tweet 15
  • Top 5 Wallets for Seamless Multi-Chain Trading in 2025

    85 shares
    Share 34 Tweet 21
  • Cross-Chain Liquidity, Meet Reality: Why 2026’s Bridge Wars Look Different

    9 shares
    Share 4 Tweet 2
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

There are currently no events.

Latest on Web3Wire

  • ThriveSparrow Advances Automated Employee Lifecycle Listening to Help Organizations Detect Attrition Risk Sooner
  • Moburst Secures $11.8M Investment from Chrysalis Holdings to Accelerate Digital Capabilities and Client Growth
  • FLYR Powers Riyadh Air’s Debut as World’s First Full-Service Airline Built for Modern Retailing
  • &money reports 100% revenue growth, DKK 10M net profit, and targets 1M+ meetings in 2026
  • WISeKey and SEALSQ Announce Roadmap and Launch of Official Website for WISeRobot.ch, Integrating Human-Centric AI With Post-Quantum Security in Robotics

RSS Latest on Block3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age

RSS Latest on Meta3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Founder’s Note
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Web3Wire Whitepaper | Tokenomics

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!

The Klyrox Protocol | The Algorithmic Monographs

Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News

Media Portfolio: Block3Wire | Meta3Wire

  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.