SHADOW-EARTH-045 is a temporary intrusion set associated with the use of the PeckBirdy JScript-based command-and-control framework in operations targeting Asian government entities and private organizations. Activity attributed to this cluster was first observed in July 2024. The intrusion set has been linked with low confidence to Earth Baxia, and the broader activity is consistent with China-aligned cyber-espionage operations, although attribution remains uncertain. The cluster has targeted government-affiliated organizations in Asia, including a Philippine educational institution. Observed tradecraft includes injecting PeckBirdy links into government websites, including login pages, to deliver credential-harvesting scripts. In private-network intrusions, the actor used MSHTA to execute PeckBirdy as a remote access channel and support lateral movement. The actor also developed a .NET executable that launched PeckBirdy through ScriptControl, reflecting deliberate use of legacy Windows scripting components and living-off-the-land execution paths. PeckBirdy enables cross-environment execution in browsers, MSHTA, Windows Script Host, Classic ASP, Node.js, and .NET ScriptControl. In SHADOW-EARTH-045 operations it was used for browser-based credential theft, remote access, and follow-on post-compromise activity. The framework supports staged delivery of additional scripts and flexible command-and-control, helping reduce persistent artifacts and complicate detection. High-confidence observed behaviors for SHADOW-EARTH-045 include credential theft, initial access through web compromise and script injection, lateral movement, post-exploitation remote access, and defense evasion through LOLBin abuse. Known associated naming includes the alias Earth Baxia, but that linkage is assessed only at low confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign using PeckBirdy against Asian government entities and private organizations, including injected PeckBirdy links on government websites for credential harvesting and MSHTA-based execution on compromised IIS servers for remote access and lateral movement.
Trend Micro-tracked China-linked activity cluster (low-confidence linkage to Earth Baxia) using the PeckBirdy C2 framework for espionage-oriented intrusions against Asian private organizations and government-affiliated entities, leveraging multiple execution environments and LOLBins for flexible deployment.
Campaign/activity cluster (assessed China-aligned) targeting Asian government entities (and a Philippine educational institution) using web injection to deliver PeckBirdy for credential harvesting and remote access/lateral movement; associated with GrayRabbit and newly identified HoloDonut backdoor; also used MSHTA and a .NET launcher leveraging ScriptControl.
China-aligned intrusion set observed from July 2024 targeting Asian government entities and private organizations (including an educational institution in the Philippines) by injecting PeckBirdy links into government websites, likely for credential harvesting and as a remote access channel; associated infrastructure includes an IP previously linked to Earth Baxia and APT41.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.