A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
2026-05-06T08:51:43Z•247cdcccc846845a5ae3a538e847aa9da2de02862e6f2dc6c44dddf0cb017b01
APTAndroid-malwareDynoWiperEDR-killersGopherWhisperMongoliaNFC-payment-appNGatePromptSpySandwormScarCruftWindows-malwareYanbianbackdoorgaming-platformgenai-malwareransomwaresupply-chain-attacktargeted-attacktrojanized-app
What happened
This ESET WeLiveSecurity feed highlights active APT and malware activity and trends. The lead report describes a supply-chain attack by the ScarCruft APT that trojanized Windows and Android games to deliver backdoors targeting the Yanbian region. Other research items cover new and resurgent threats: GopherWhisper (China‑aligned APT) targeting Mongolian government institutions; a new NGate variant hidden in a trojanized NFC payment app; PromptSpy, the first known Android malware abusing generative AI in its execution flow; DynoWiper and Sandworm-related destructive activity; analyses of EDR-kll
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- 247cdcccc846845a5ae3a538e847aa9da2de02862e6f2dc6c44dddf0cb017b01
- Enrichment time
- 2026-05-06T08:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.