China-Backed 'PeckBirdy' Takes Flight for Cross-Platform Attacks
ID: 9eba2931-bfb9-5519-b9b5-4bf00d25c1c3
STIX ID: report--9eba2931-bfb9-5519-b9b5-4bf00d25c1c3
Feed Name: Dark Reading
Date Published: 2026-01-28
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Trend Micro researchers tracked a cross-platform JScript command-and-control framework named "PeckBirdy" used since 2023 by likely China-aligned actors in two separate campaigns (Shadow-Void-044 targeting gambling sites and Shadow-Earth-045 targeting government entities). Attackers leveraged dynamically injected JScript, living-off-the-land binaries, stolen code-signing certificates, Cobalt Strike, a Chrome RCE (CVE-2020-16040), and modular backdoors (MKDoor, HoloDonut and GrayRabbit) to conduct credential harvesting, remote access and lateral movement; Trend Micro provides IOCs and hunting guidance and urges continuous defensive monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
