Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»PeckBirdy Framework Tied to China-Aligned Cyber Campaigns
Cyber Security

PeckBirdy Framework Tied to China-Aligned Cyber Campaigns

Team-CWDBy Team-CWDJanuary 27, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A previously undocumented script-based command-and-control (C2) framework has been linked to multiple cyber campaigns targeting gambling companies, government bodies and private organizations across Asia.

The framework, dubbed PeckBirdy, has been active since 2023 and has been attributed to China-aligned advanced persistent threat (APT) groups based on observed infrastructure and tactics.

PeckBirdy is built using JScript, an older scripting language that allows it to operate across a wide range of execution environments.

This design enables attackers to deploy the framework using living-off-the-land binaries (LOLBins), adapting it for different stages of an attack. Researchers observed it functioning as a watering-hole controller, a reverse shell and a C2 server, depending on context.

Two Separate Campaigns

Two campaigns using PeckBirdy have been identified by Trend Micro and tracked as SHADOW-VOID-044 and SHADOW-EARTH-045.

The first focused largely on Chinese gambling websites, where malicious scripts were injected to deliver fake Google Chrome update prompts. Victims who downloaded the updates unknowingly installed attacker-controlled backdoors.

The second campaign, observed in July 2024, targeted Asian government entities and private organizations. In these cases, PeckBirdy links were embedded into compromised government websites or executed via MSHTA to enable credential harvesting and lateral movement.

Read more on malicious JavaScript frameworks: Threat Actors Shift to JavaScript-Based Phishing Attacks

Modular Backdoors Extend Capabilities

PeckBirdy’s core functionality is supplemented by at least two modular backdoors, HOLODONUT and MKDOOR, both linked to SHADOW-VOID-044. These tools allow attackers to extend functionality after initial compromise.

Key capabilities observed include:

  • Delivery of additional payloads via modular plugins

  • In-memory execution to reduce forensic visibility

  • Use of social engineering and browser exploits to gain access

HOLODONUT is a .NET-based backdoor that disables security features such as AMSI before executing payloads in memory. MKDOOR, by contrast, disguises its network traffic as legitimate Microsoft support or activation pages and attempts to evade Microsoft Defender by altering exclusion settings.

Infrastructure overlaps and shared tooling suggest SHADOW-VOID-044 is linked with UNC3569, a China-aligned group previously associated with the GRAYRABBIT backdoor.

Some samples also used stolen code-signing certificates to legitimize malicious Cobalt Strike payloads. SHADOW-EARTH-045 showed weaker but notable ties to activity previously attributed to Earth Baxia.

“Detecting malicious JavaScript frameworks remains a significant challenge due to their use of dynamically generated, runtime-injected code and the absence of persistent file artifacts, enabling them to evade traditional endpoint security controls,” Trend Micro wrote.

“In this environment, adaptability and continuous refinement of defensive strategies are no longer optional, but fundamental to maintaining operational integrity in an increasingly hostile digital landscape.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleDrowning in spam or scam emails lately? Here’s why
Next Article How Smart MSSPs Using AI to Boost Margins with Half the Staff
Team-CWD
  • Website

Related Posts

Cyber Security

Cisco Vulnerability Exploited Months Before Disclosure, Google Warns

June 25, 2026
Cyber Security

Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Espionage

June 25, 2026
Cyber Security

UK Museums Face Cybersecurity Risks, MPs Warn

June 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Find your weak spots before attackers do

November 21, 2025

What are brushing scams and how do I stay safe?

December 24, 2025

How cybercriminals are targeting content creators

November 26, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.