logo

China-Backed 'PeckBirdy' Takes Flight for Cross-Platform Attacks

ID: 9eba2931-bfb9-5519-b9b5-4bf00d25c1c3

STIX ID: report--9eba2931-bfb9-5519-b9b5-4bf00d25c1c3

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-01-28

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Trend Micro researchers tracked a cross-platform JScript command-and-control framework named "PeckBirdy" used since 2023 by likely China-aligned actors in two separate campaigns (Shadow-Void-044 targeting gambling sites and Shadow-Earth-045 targeting government entities). Attackers leveraged dynamically injected JScript, living-off-the-land binaries, stolen code-signing certificates, Cobalt Strike, a Chrome RCE (CVE-2020-16040), and modular backdoors (MKDoor, HoloDonut and GrayRabbit) to conduct credential harvesting, remote access and lateral movement; Trend Micro provides IOCs and hunting guidance and urges continuous defensive monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.