Stealth in Script: “PeckBirdy” Framework Powers New Wave of China-Aligned Attacks
ID: 5f8fa448-0e7b-57e4-a633-61fb20f714ee
STIX ID: report--5f8fa448-0e7b-57e4-a633-61fb20f714ee
Feed Name: securityonline.info
PeckBirdy is a lightweight, JScript-based fileless command-and-control framework used by China-aligned APT actors since 2023 to target Asian government entities, the gambling industry, and educational institutions; it leverages Windows Script Host and runtime code injection to avoid persistent artifacts and detection, and is deployed with modular backdoors (HOLODONUT, MKDOOR) across campaigns that have used stolen code-signing certificates, Cobalt Strike, and exploited CVE-2020-16040.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
