logo

Stealth in Script: “PeckBirdy” Framework Powers New Wave of China-Aligned Attacks

ID: 5f8fa448-0e7b-57e4-a633-61fb20f714ee

STIX ID: report--5f8fa448-0e7b-57e4-a633-61fb20f714ee

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-01-27

Date Updated: 2026-04-23

Author: Ddos

...
...

PeckBirdy is a lightweight, JScript-based fileless command-and-control framework used by China-aligned APT actors since 2023 to target Asian government entities, the gambling industry, and educational institutions; it leverages Windows Script Host and runtime code injection to avoid persistent artifacts and detection, and is deployed with modular backdoors (HOLODONUT, MKDOOR) across campaigns that have used stolen code-signing certificates, Cobalt Strike, and exploited CVE-2020-16040.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.