logo

PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups

ID: 4f96101a-7e5b-5e28-a006-4bf82e82bc54

STIX ID: report--4f96101a-7e5b-5e28-a006-4bf82e82bc54

Feed Name: TrendAI Security Blog

Threat Score
85/100

Date Published: 2026-01-01

Date Updated: 2026-08-06

...
...

This report analyzes a versatile JScript-based command-and-control framework named PeckBirdy used since 2023 in at least two campaigns (SHADOW-VOID-044 and SHADOW-EARTH-045) targeting Chinese gambling sites and Asian government/private organizations; it describes delivery via website injections and LOLBins, detailed C2 protocols and configs, two modular backdoors (HOLODONUT and MKDOOR), associated tooling (NEXLOAD, Donut, Cobalt Strike), observed TTPs for credential theft and lateral movement, and attribution links to multiple China-aligned APTs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.