Trend Micro reported on PeckBirdy, a lightweight JScript-based command-and-control (C2) framework used since at least 2023 by China-aligned threat actors to reduce on-disk artifacts and evade detection by leveraging Windows Script Host and runtime-injected code. The activity was tied to two intrusion sets/campaigns, SHADOW-VOID-044 and SHADOW-EARTH-045, with victimology including Asian government entities, education, and the Chinese gambling sector. The framework was observed operating alongside modular backdoors HOLODONUT and MKDOOR, and in at least one campaign with commodity tooling such as Cobalt Strike and the use of stolen code-signing certificates.
Trend Micro’s analysis linked SHADOW-VOID-044 infrastructure and tooling to previously reported China-aligned activity, including overlap with UNC3569 (e.g., shared C2 domain center[.]myrnicrosoft[.]com and targeting of the Chinese gambling industry) and hosting of a variant of the GRAYRABBIT backdoor that used DLL sideloading and PowerShell execution via UuidFromStringA. Additional infrastructure overlaps were noted with activity associated with TheWizard (e.g., HOLODONUT samples communicating with mkdmcdn[.]com). Reported infrastructure and artifacts included IP 47[.]238[.]219[.]111, domains center[.]myrnicrosoft[.]com, mkdmcdn[.]com, and a Cobalt Strike payload with SHA-256 162cc325ab7b6e70edb6f4d0bc0e52130c56903f.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Trend Micro publicly disclosed its analysis of the PeckBirdy framework, describing two campaigns—SHADOW-VOID-044 and SHADOW-EARTH-045—and newly identified modular backdoors including HOLODONUT and MKDOOR. The report assessed possible links to several China-aligned actors, including UNC3569, TheWizards, Earth Lusca, and Earth Baxia, while noting attribution uncertainty.
In July 2024, SHADOW-EARTH-045 targeted a Philippine educational institution by using MSHTA to fetch content from github.githubassets.net and launch PeckBirdy on a compromised IIS server. The same incident also involved downloading from an IP address previously linked to Earth Baxia, though attribution remained low confidence.
A second PeckBirdy-linked intrusion set, SHADOW-EARTH-045, was first observed in July 2024 targeting Asian government entities and private organizations. The campaign used website injection, likely for credential harvesting, and leveraged LOLBins such as MSHTA and .NET ScriptControl-based launchers.
One PeckBirdy-linked campaign, tracked as SHADOW-VOID-044, injected malicious scripts into compromised Chinese gambling websites to present fake Google Chrome update pages that delivered malware. The activity also involved follow-on tooling such as HOLODONUT, MKDOOR, Cobalt Strike, and infrastructure associated with exploit and reverse-shell delivery.
Trend Micro reported that the JScript-based PeckBirdy command-and-control framework has been used by China-aligned threat activity since at least 2023. The framework was designed for fileless, living-off-the-land execution across multiple Windows and web-related environments.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
8 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcescworld.com
Open sourcedarkreading.com
Open sourcethecyberedition.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.