Last seven days
- First activity
- Sep 16, 2026
- Last activity
- Sep 16, 2026
- Feed role
- C2
- Host form
- 0 IP / 25 hostnames
PeckBirdy is a JScript-based command-and-control framework used in China-aligned intrusion activity since 2023.
Profile source: Mallory opens in a new tabPeckBirdy
PeckBirdy is a JScript-based command-and-control framework used in China-aligned intrusion activity since 2023. It is designed to operate across browser, MSHTA, Windows Script Host, Classic ASP, Node.js, and .NET ScriptControl contexts, adapting its code to the available execution environment and abusing living-off-the-land components. It primarily uses WebSocket command-and-control communications, with fallback transports for compatibility, and encrypts later-stage communications.
PeckBirdy has been used in watering-hole operations against Chinese gambling websites, where injected scripts present fake browser-update lures that lead to delivery of modular backdoors including HOLODONUT and MKDOOR. It has also been used against Asian government entities and private organizations, including activity involving injected government login pages for credential theft and MSHTA-based remote access and lateral movement. Related infrastructure has been concealed behind Chinese-language casino and adult-themed decoy sites, including through browser service workers and WebSocket connections.
The framework can deliver environment-specific second-stage scripts supporting credential theft, reverse-shell access, browser exploitation, social engineering, and backdoor delivery. SHADOW-VOID-044, the gambling-site campaign, has a moderate-to-high-confidence link to UNC3569. SHADOW-EARTH-045, which targeted Asian government and private-sector organizations from at least July 2024, has a low-confidence association with Earth Baxia.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
Since 2023, we have been observing threat campaigns employing a previously unseen script-based command-and-control (C&C) framework which we named PeckBirdy... PeckBirdy is a script-based framework... implemented using JScript... observed PeckBirdy in various kill chain stages, including being used as a watering-hole control server during the initial attack phase, as a reverse shell server during the lateral movement phase, and as a C&C server during the backdoor phase.
Since 2023, we have been observing threat campaigns employing a previously unseen script-based command-and-control (C&C) framework which we named PeckBirdy... PeckBirdy is a script-based framework... implemented using JScript... observed PeckBirdy in various kill chain stages, including being used as a watering-hole control server during the initial attack phase, as a reverse shell server during the lateral movement phase, and as a C&C server during the backdoor phase.
Researchers have identified PeckBirdy, a versatile JScript-based C2 framework, deployed since 2023 in campaigns linked to China-aligned APT actors.
Researchers have identified PeckBirdy, a versatile JScript-based C2 framework, deployed since 2023 in campaigns linked to China-aligned APT actors.
Researchers have tracked the versatile JScript-based command-and-control framework PeckBirdy since 2023, used by China-aligned threat actors in two distinct campaigns...
Exploited software
MITRE ATT&CK
Reporting
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.