PeckBirdy is a JScript-based command-and-control framework used in China-aligned intrusion activity since 2023. It is designed to operate across browser, MSHTA, Windows Script Host, Classic ASP, Node.js, and .NET ScriptControl contexts, adapting its code to the available execution environment and abusing living-off-the-land components. It primarily uses WebSocket command-and-control communications, with fallback transports for compatibility, and encrypts later-stage communications.
PeckBirdy has been used in watering-hole operations against Chinese gambling websites, where injected scripts present fake browser-update lures that lead to delivery of modular backdoors including HOLODONUT and MKDOOR. It has also been used against Asian government entities and private organizations, including activity involving injected government login pages for credential theft and MSHTA-based remote access and lateral movement. Related infrastructure has been concealed behind Chinese-language casino and adult-themed decoy sites, including through browser service workers and WebSocket connections.
The framework can deliver environment-specific second-stage scripts supporting credential theft, reverse-shell access, browser exploitation, social engineering, and backdoor delivery. SHADOW-VOID-044, the gambling-site campaign, has a moderate-to-high-confidence link to UNC3569. SHADOW-EARTH-045, which targeted Asian government and private-sector organizations from at least July 2024, has a low-confidence association with Earth Baxia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The scripts we found included: The exploitation script for the CVE-2020-16040 vulnerability affecting Google Chrome | Since 2023, we have been observing threat campaigns employing a previously unseen script-based command-and-control (C&C) framework which we named PeckBirdy... PeckBirdy is a script-based framework... implemented using JScript... observed PeckBirdy in various kill chain stages, including being used as a watering-hole control server during the initial attack phase, as a reverse shell server during the lateral movement phase, and as a C&C server during the backdoor phase.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since 2023, we have been observing threat campaigns employing a previously unseen script-based command-and-control (C&C) framework which we named PeckBirdy... PeckBirdy is a script-based framework... implemented using JScript... observed PeckBirdy in various kill chain stages, including being used as a watering-hole control server during the initial attack phase, as a reverse shell server during the lateral movement phase, and as a C&C server during the backdoor phase.
Since 2023, we have been observing threat campaigns employing a previously unseen script-based command-and-control (C&C) framework which we named PeckBirdy... PeckBirdy is a script-based framework... implemented using JScript... observed PeckBirdy in various kill chain stages, including being used as a watering-hole control server during the initial attack phase, as a reverse shell server during the lateral movement phase, and as a C&C server during the backdoor phase.
Researchers have identified PeckBirdy, a versatile JScript-based C2 framework, deployed since 2023 in campaigns linked to China-aligned APT actors.
Researchers have identified PeckBirdy, a versatile JScript-based C2 framework, deployed since 2023 in campaigns linked to China-aligned APT actors.
Researchers have tracked the versatile JScript-based command-and-control framework PeckBirdy since 2023, used by China-aligned threat actors in two distinct campaigns...
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The framework has been linked to secondary tools that can run commands, steal credentials, and provide remote access.
"Delivered scripts observed include... TCP reverse shell establishment."
One observed page registered a JavaScript service worker and loaded a suspicious script resembling earlier PeckBirdy code... asg78.com [was] observed loading a suspicious JavaScript payload.
The subsequent communication is encrypted using AES and then encoded with Base64, with the AES encryption key being the ATTACK ID value from the configuration.
Online casinos are being used to disguise and deploy malicious threats... Chinese-language casino websites... prompt targets to download what they believe is software for the casino experience.
“PeckBirdy can also lead victims to false browser-update prompts that deliver backdoors.”
"execution through various living-off-the-land binaries (LOLBins)... such as browsers, MSHTA, WScript..."; "employing MSHTA for lateral movement"
...in another incident, we noticed the attacker using MSHTA to execute PeckBirdy as a remote access channel for lateral movement in a private organization.
Upon initial execution, PeckBirdy searches for unique objects that exist only in specific environments to determine the current execution context. It checks for the window object in browser environments, the process object in NodeJS environment, the response object in ASP environment, and the presence of the APPLICATION tag within the HTML in HTA environments.
“The framework has been linked to secondary tools that can run commands, steal credentials, and provide remote access.”
We discovered that this campaign injects PeckBirdy links into government websites, likely to deliver scripts for credential harvesting on the website. In one case, the injection was on a login page of a government’s system...
In a local host environment such as HTA, it attempts to retrieve hardware information from the motherboard and hard drive on the victim’s machines. It then combines this information with MD5 to generate a hash value which serves as the victim ID.
Upon initial execution, PeckBirdy searches for unique objects that exist only in specific environments to determine the current execution context. It checks for the window object in browser environments, the process object in NodeJS environment, the response object in ASP environment, and the presence of the APPLICATION tag within the HTML in HTA environments.
“China-aligned APT groups have been running the PeckBirdy framework since 2023, hiding their malware C2 domains inside low-quality Chinese-language casino websites.”
PeckBirdy C2 and Decoy Domains (Type 3)... lack of detections on VirusTotal for some PeckBirdy C2s raises concerns about how this Chinese APT threat is being tracked.
"The threat actor also simultaneously downloaded files from 47[.]238[.]184[.]9..."
10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A script-based malware/backdoor delivered through Chinese-language gambling websites masquerading as casino software updates. It uses C2 and decoy domains to provide China-aligned APT actors persistent access to compromised endpoints.
A JavaScript-based command-and-control framework concealed in casino-themed and Chinese-language adult websites. It uses embedded scripts, service workers, and WebSocket connections to maintain covert communications with attacker-controlled infrastructure; it can also direct victims to fake browser-update prompts delivering backdoors.
A JavaScript-based command-and-control framework that uses disposable casino and adult-themed websites as decoy infrastructure. It can maintain background browser communications through service workers and WebSockets, redirect victims to fake browser updates delivering backdoors, and is linked to secondary tools for command execution, credential theft, and remote access.
A script-based attacker framework loaded through compromised websites. Operators conceal its command-and-control domains within Chinese-language gambling sites and have injected scripts that load PeckBirdy and present fake software-update pages to induce victims to download malware.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.