SHADOW-VOID-044 is a temporary intrusion set associated with use of the PeckBirdy JScript-based command-and-control framework in campaigns observed since 2023. The cluster is linked with moderate-to-high confidence to UNC3569 and is assessed as China-aligned based on overlapping infrastructure and victimology. Its activity has centered on compromises of Chinese gambling websites, where malicious script injections were used as watering-hole mechanisms to load PeckBirdy in victims’ browsers and present fake Google Chrome update lures that delivered attacker-prepared backdoors. The intrusion set has used PeckBirdy as a flexible, cross-environment framework capable of operating through browsers and Windows scripting components, enabling staged payload delivery and follow-on access. Infrastructure associated with SHADOW-VOID-044 also hosted scripts for cookie theft, reverse shells, social-engineering delivery, and exploitation of CVE-2020-16040. Reported malware linked to the cluster includes MKDOOR, HOLODONUT, GRAYRABBIT, NEXLOAD, and Cobalt Strike. HOLODONUT is a modular .NET backdoor delivered by the NEXLOAD downloader, while MKDOOR is another modular backdoor delivered through fake browser-update phishing pages. Observed tradecraft includes watering-hole compromise, social-engineering-based malware delivery, credential- and session-related theft through browser cookie collection, in-memory execution of .NET payloads, AMSI and event-tracing suppression, and Microsoft Defender exclusion abuse for evasion. Additional execution techniques reported in the cluster include DLL sideloading and PowerShell-based payload decoding and execution. The actor’s tooling and infrastructure overlap with other China-linked clusters illustrates the broader ecosystem of shared malware, certificates, and operational resources among Chinese intrusion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign using the PeckBirdy script-based C2 framework against Chinese gambling websites via watering-hole style compromises, fake Chrome update lures, credential/cookie theft, exploitation delivery, reverse shells, and modular backdoors including HOLODONUT and MKDOOR.
Trend Micro-tracked China-linked activity cluster assessed to have run a financially motivated watering-hole campaign on Chinese gambling sites using the PeckBirdy C2 framework to deliver modular backdoors and steal credentials; infrastructure overlaps with other clusters were noted.
Campaign/activity cluster (assessed China-aligned) targeting Chinese gambling websites since 2023 using PeckBirdy to deliver/execute JScript and deploy backdoors (including MKDoor), leveraging fake Chrome update lures, stolen code-signing certs, Cobalt Strike, and Chrome RCE exploitation for persistence.
China-aligned intrusion set using the PeckBirdy JScript-based C2 framework since 2023, including web injection/watering-hole style activity against Chinese gambling sites to deliver fake Chrome update lures and modular backdoors (e.g., HOLODONUT, MKDOOR), with LOLBins (e.g., MSHTA) used for execution and lateral movement.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.