Last updated 1 month ago
ESET researchers disclosed a supply-chain attack targeting the Yanbian gaming community in China, attributed to the North Korean APT group ScarCruft (APT37). The attackers compromised a Yanbian gaming site to distribute trojanized versions of legitimate Windows and Android gaming software. The campaign was discovered and publicly disclosed in June 2026; no internal discovery date was provided. The number of affected users or systems was not quantified.
The attack chain began with the compromise of the gaming platform's software distribution mechanism, replacing legitimate installers with trojanized variants. On Windows, the malicious payload delivered a backdoor capable of keylogging, screen capture, microphone and webcam recording, and file exfiltration. On Android, the trojanized app requested extensive permissions to harvest contacts, SMS messages, call logs, and device location. ScarCruft is known for using spear-phishing and watering hole attacks, but this incident marks a shift to supply-chain compromise. Exfiltrated data types include user credentials, system information, keystrokes, screenshots, audio/video recordings, and arbitrary files.
No post-incident developments such as regulatory actions, litigation, ransom payments, or remediation milestones were reported in the article.
Supply-chain attack: trojanized Windows and Android software distributed via compromised gaming site
This supply-chain attack on a gaming platform underscores the need for software integrity verification, such as code signing and checksum validation, especially for platforms distributing executables to end users. The compromise of the distribution channel allowed ScarCruft to bypass traditional endpoint defenses, highlighting the importance of application whitelisting and behavioral detection for trojanized software. Organizations in the gaming and entertainment sectors should implement strict vendor risk management and monitor for anomalous software behavior post-installation.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor