#BirdCall
Malware/Tool
2026-05-05 • A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
BirdCall is a multiplatform backdoor and Android spyware family developed by the North Korea-aligned ScarCruft group for espionage. Android versions were distributed through trojanized games on a compromised Yanbian-focused gaming platform; another sample repackaged and impersonated the Zangi messenger. It collects device details, contacts, call and SMS histories, directory listings, selected files, and other personal data, and can take screenshots and voice recordings. BirdCall polls Zoho WorkDrive for commands and uses a separate account for exfiltration, encrypting and obfuscating stolen data before upload.
-
2
Tagged Reports
-
2
Unique Authors
-
70
Active Days