Shadow-Earth-045 is a temporary intrusion set associated with China-aligned cyber activity and assessed with low confidence to overlap with Earth Baxia. The cluster has been active since at least July 2024 and has targeted Asian government entities and private organizations, including a Philippine educational institution. Its operations are consistent with cyber-espionage, particularly credential harvesting and follow-on intrusion activity against government-affiliated environments. Shadow-Earth-045 is notable for using the JScript-based PeckBirdy framework, a cross-environment command-and-control and delivery platform designed to run through multiple Windows and web execution contexts, including MSHTA and .NET ScriptControl, while abusing living-off-the-land binaries and legacy scripting components. In observed intrusions, the actor injected PeckBirdy links into government websites, including login pages, to deliver credential-harvesting scripts. It also used MSHTA to execute PeckBirdy as a remote-access channel and for lateral movement inside a private organization, and developed a .NET launcher to trigger PeckBirdy through ScriptControl. The intrusion set has been associated with modular malware delivery and post-compromise tooling, including HOLODONUT and, in some reporting, GRAYRABBIT. HOLODONUT is a modular backdoor capable of loading and managing plugins from a command server. PeckBirdy’s design emphasizes stealth and flexibility through dynamically generated, runtime-injected JavaScript and minimal persistent artifacts, complicating detection and attribution. Shadow-Earth-045 is one of multiple PeckBirdy-using clusters and appears distinct from Shadow-Void-044, though both are assessed as part of a broader ecosystem of shared tooling and infrastructure among China-aligned operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trend Micro-tracked China-linked activity cluster (low-confidence linkage to Earth Baxia) using the PeckBirdy C2 framework for espionage-oriented intrusions against Asian private organizations and government-affiliated entities, leveraging multiple execution environments and LOLBins for flexible deployment.
Campaign/activity cluster (assessed China-aligned) targeting Asian government entities (and a Philippine educational institution) using web injection to deliver PeckBirdy for credential harvesting and remote access/lateral movement; associated with GrayRabbit and newly identified HoloDonut backdoor; also used MSHTA and a .NET launcher leveraging ScriptControl.
China-aligned intrusion set observed from July 2024 targeting Asian government entities and private organizations (including an educational institution in the Philippines) by injecting PeckBirdy links into government websites, likely for credential harvesting and as a remote access channel; associated infrastructure includes an IP previously linked to Earth Baxia and APT41.
Temporary intrusion set observed targeting a Philippine educational institution; used MSHTA to fetch content from githubassets infrastructure to launch PeckBirdy on a compromised IIS server. Low-confidence linkage to Earth Baxia based on shared IP/domain infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.