PeckBirdy Framework Tied to China-Aligned Cyber Campaigns
ID: 3fcae075-7539-5f42-8990-498e658f3de4
STIX ID: report--3fcae075-7539-5f42-8990-498e658f3de4
Feed Name: Infosecurity Magazine (News)
Trend Micro researchers describe PeckBirdy, a JScript-based command-and-control framework active since 2023 and used in multiple campaigns against gambling websites, Asian government entities, and private organizations. The framework supports modular backdoors (HOLODONUT and MKDOOR), leverages living-off-the-land binaries, in-memory execution, and social-engineering/browser exploits (watering-hole, fake Chrome updates, MSHTA) to harvest credentials, deploy backdoors, and move laterally; infrastructure overlap and tooling link activity to China-aligned APT actors such as UNC3569.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
