Skip to content

PeckBirdy

PeckBirdy is a JScript-based command-and-control framework used in China-aligned intrusion activity since 2023.

Profile source: Mallory opens in a new tab

PeckBirdy

Family profile

PeckBirdy is a JScript-based command-and-control framework used in China-aligned intrusion activity since 2023. It is designed to operate across browser, MSHTA, Windows Script Host, Classic ASP, Node.js, and .NET ScriptControl contexts, adapting its code to the available execution environment and abusing living-off-the-land components. It primarily uses WebSocket command-and-control communications, with fallback transports for compatibility, and encrypts later-stage communications.

PeckBirdy has been used in watering-hole operations against Chinese gambling websites, where injected scripts present fake browser-update lures that lead to delivery of modular backdoors including HOLODONUT and MKDOOR. It has also been used against Asian government entities and private organizations, including activity involving injected government login pages for credential theft and MSHTA-based remote access and lateral movement. Related infrastructure has been concealed behind Chinese-language casino and adult-themed decoy sites, including through browser service workers and WebSocket connections.

The framework can deliver environment-specific second-stage scripts supporting credential theft, reverse-shell access, browser exploitation, social engineering, and backdoor delivery. SHADOW-VOID-044, the gambling-site campaign, has a moderate-to-high-confidence link to UNC3569. SHADOW-EARTH-045, which targeted Asian government and private-sector organizations from at least July 2024, has a low-confidence association with Earth Baxia.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Initial Access
  • Lateral Movement
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 16, 2026
Last activity
Sep 16, 2026
Feed role
C2
Host form
0 IP / 25 hostnames

Leading locations

  • US10
  • HK7
  • NL2
  • JP1

Leading providers

  • Cloudflare, Inc.6
  • Microsoft Corporation2
  • NALMI LIMITED2
  • Amazon.com, Inc.1
  • Dimension Network & Communication Limited1
  • DXTL Tseung Kwan O Service1

Infrastructure traits

  • Hosting 19
  • Anycast 9

Reported operators

Threat actors

5 named in public reporting
UNC3569

Since 2023, we have been observing threat campaigns employing a previously unseen script-based command-and-control (C&C) framework which we named PeckBirdy... PeckBirdy is a script-based framework... implemented using JScript... observed PeckBirdy in various kill chain stages, including being used as a watering-hole control server during the initial attack phase, as a reverse shell server during the lateral movement phase, and as a C&C server during the backdoor phase.

Earth Baxia

Since 2023, we have been observing threat campaigns employing a previously unseen script-based command-and-control (C&C) framework which we named PeckBirdy... PeckBirdy is a script-based framework... implemented using JScript... observed PeckBirdy in various kill chain stages, including being used as a watering-hole control server during the initial attack phase, as a reverse shell server during the lateral movement phase, and as a C&C server during the backdoor phase.

Earth Lusca

Researchers have identified PeckBirdy, a versatile JScript-based C2 framework, deployed since 2023 in campaigns linked to China-aligned APT actors.

TheWizards

Researchers have identified PeckBirdy, a versatile JScript-based C2 framework, deployed since 2023 in campaigns linked to China-aligned APT actors.

SHADOW-EARTH-045

Researchers have tracked the versatile JScript-based command-and-control framework PeckBirdy since 2023, used by China-aligned threat actors in two distinct campaigns...

Exploited software

Vulnerabilities linked to PeckBirdy

1 CVEs

MITRE ATT&CK

PeckBirdy in ATT&CK

25 distinct techniques

Reporting

Research mentioning PeckBirdy

Aug 19
Trendai Security

PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups | TrendAI (US)

Researchers detailed multiple China-aligned intrusion sets using modular tooling to compromise targets across Windows, web, and mobile environments. ESET said TheWizards used a tool called Spellbinder to abuse IPv6 SLAAC by sending rogue ICMPv6 Router Advertisements, positioning the attackers as the default gateway for adversary-in-the-middle operations. The group then intercepted DNS requests for Chinese software vendors and redirected update traffic so legitimate applications such as Tencent QQ and previously Sogou Pinyin fetched malicious payloads instead of real updates. The resulting infection chain used a downloader DLL, an encrypted blob, and in-memory loading of the WizardNet backdoor, which patched AMSI and ETW, supported modular execution, and injected shellcode into other processes while maintaining encrypted command-and-control. Separate reporting described broader China-linked operations using flexible malware delivery and post-compromise frameworks. Trend Micro tied Earth Minotaur to the MOONSHINE Exploit Kit and the DarkNimbus Android backdoor, while TrendAI documented PeckBirdy, a JScript-based framework used since 2023 across browsers, MSHTA, WScript, Classic ASP, Node.js, and .NET ScriptControl for watering-hole attacks, credential theft, lateral movement, reverse shells, and persistent backdoor access. PeckBirdy was observed in campaigns against Chinese gambling sites, Asian government entities, and private organizations, alongside modular backdoors HOLODONUT and MKDOOR. The reporting also noted infrastructure and tooling overlaps linking some of these activities to UNC3569, Earth Baxia, and supplier UPSEC, underscoring an ecosystem of China-aligned operators reusing shared malware, hijacking infrastructure, and fake software-update lures.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.