PeckBirdy: The Sophisticated JavaScript Framework Powering China-Aligned APT Campaigns

Listen to this Post

Featured Image
Cybersecurity researchers have uncovered a highly versatile JavaScript-based command-and-control (C&C) framework named PeckBirdy, actively used by China-aligned advanced persistent threat (APT) groups since 2023. This framework exploits living-off-the-land binaries (LOLBins) to infiltrate a wide range of environments, delivering modular backdoors like HOLODONUT and MKDOOR. Its operations have primarily targeted gambling industries across China and several Asian government and private organizations, highlighting the growing sophistication of modern APT operations.

PeckBirdy leverages old yet flexible JScript to bypass environmental restrictions, enabling execution in browsers, MSHTA, WScript, NodeJS, Classic ASP, and .NET via ScriptControl. Its modular design allows attackers to pivot seamlessly across attack stages—from initial watering-hole injections to lateral movement and persistent backdoor control—without triggering conventional endpoint security.

Tracking PeckBirdy in the Wild

First observed in 2023, PeckBirdy was found embedded in malicious scripts injected into gambling websites. Victims visiting these sites would unknowingly execute PeckBirdy scripts, which presented fake Chrome update pages to trick users into downloading malicious backdoors. This operation, tracked under SHADOW-VOID-044, represents one of the earliest identified campaigns.

In mid-2024, another campaign, SHADOW-EARTH-045, targeted Asian government entities and private organizations. PeckBirdy scripts were injected into official websites, including login pages, to harvest credentials. In certain cases, attackers used MSHTA to execute PeckBirdy for lateral movement and deployed .NET executables to launch scripts via ScriptControl. These operations demonstrate PeckBirdy’s ability to adapt to multiple environments and deployment methods, emphasizing its flexibility and modularity.

Deep Dive: PeckBirdy Framework Capabilities

PeckBirdy executes differently depending on the environment:

Browser environments: Sandbox limitations restrict actions to the webpage scope. Victim IDs are stored in browser cookies.

MSHTA/Local execution: Full access to the machine enables hardware-based victim ID generation and broader command execution.

Communication methods: Defaults to WebSocket, but can fallback to Flash ActiveX, Comet, or LocalComet protocols depending on environment compatibility.

Script delivery: Uses multiple APIs to download environment-specific scripts for MSHTA, WScript, Classic ASP, and HTML execution.

Victim tracking: Generates unique victim IDs using hardware info or random strings, stored either in cookies or temporary files.

The framework incorporates AES encryption for server communications, dynamically switches between ECMAScript 3 and 5 functions, and can execute scripts for diverse attack stages, including cookie theft, social engineering pop-ups, exploit deployment (CVE-2020-16040), reverse shells, and additional backdoor installations via ElectronJS.

Modular Backdoors: HOLODONUT and MKDOOR

HOLODONUT

HOLODONUT is a .NET-based modular backdoor deployed via a downloader named NEXLOAD. It uses advanced evasion techniques like AMSI and ETW disabling, in-memory execution via Donut, and plugin-based modular commands. Key functionalities include loading, executing, and unloading plugins, collecting system information, and providing a stealthy remote access channel.

MKDOOR

MKDOOR is a modular backdoor composed of a downloader and the backdoor module itself. It evades detection by masquerading as Microsoft support or Windows activation URLs and adds itself to Microsoft Defender exclusion lists. MKDOOR’s capabilities depend on the modules delivered by the C&C server, supporting commands such as INSTALL, EXECUTE, UNINSTALL, SLEEP, and EXIT, enabling flexible execution of attacker-defined tasks.

Campaign Attribution

PeckBirdy campaigns have been attributed to multiple China-aligned APT actors:

SHADOW-VOID-044: Linked to UNC3569 and TheWizard, targeting Chinese gambling industries using HOLODONUT and the GRAYRABBIT backdoor. Some infrastructure overlaps with previous BIOPASS RAT campaigns.

SHADOW-EARTH-045: Targeted Asian government institutions, potentially linked to Earth Baxia, though attribution confidence remains low.

Shared techniques include stolen code-signing certificates, sophisticated evasion methods, and modular backdoor deployment, demonstrating coordinated activity across multiple actors.

What Undercode Say:

PeckBirdy represents a new wave of adaptable, script-based C&C frameworks designed to exploit existing system tools rather than relying on traditional malware files. Its flexibility across environments—browser, local execution, and server-side—shows a deep understanding of defensive blind spots, allowing threat actors to maintain persistent access with minimal detection risk.

The modular backdoors, HOLODONUT and MKDOOR, extend PeckBirdy’s operational impact by offering plug-and-play capabilities for espionage, credential theft, and system control. Notably, the use of old technologies like JScript, combined with modern encryption and obfuscation techniques, indicates a deliberate strategy: evade automated detection while maximizing cross-platform compatibility.

PeckBirdy’s campaigns also illustrate the layered sophistication of China-aligned APTs. By combining credential harvesting, supply-chain-like infections, and social engineering, attackers maximize the attack surface while minimizing traceable footprints. The observed reuse of infrastructure and stolen certificates across campaigns indicates both collaboration and operational efficiency among threat groups.

For defenders, traditional endpoint detection may struggle against dynamic, in-memory script execution. Security operations must pivot to behavior-based analysis, anomaly detection, and real-time monitoring of network communication patterns. Tools like TrendAI Vision One™ offer enhanced visibility into these complex threat frameworks through automated IoC monitoring, threat hunting queries, and AI-driven intelligence feeds.

PeckBirdy also demonstrates that APTs are increasingly leveraging web-based attack vectors. Watering-hole attacks and embedded scripts in legitimate websites remain high-risk areas, suggesting that continuous monitoring of third-party web assets is essential for proactive cybersecurity posture.

The strategic takeaway is clear: modularity, flexibility, and environmental awareness are the cornerstones of modern APT campaigns. Defenders must adopt equally dynamic and adaptive defenses to mitigate these evolving threats.

Fact Checker Results:

✅ PeckBirdy framework confirmed to target gambling and government entities in Asia.
✅ HOLODONUT and MKDOOR backdoors confirmed as modular and capable of in-memory execution.

❌ Attribution to Earth Baxia for SHADOW-EARTH-045 remains low-confidence.

Prediction:

Given the observed evolution, PeckBirdy-style frameworks are likely to become a template for future APT operations. Expect more script-based, cross-platform malware leveraging LOLBins, combined with modular backdoors capable of bypassing traditional defenses. 🌐 The continued use of stolen certificates and infrastructure sharing may lead to even more coordinated multi-industry campaigns, especially targeting financial, government, and education sectors in Asia and beyond. 🔐 Organizations that do not implement behavior-based monitoring and threat-hunting capabilities may increasingly face persistent, stealthy intrusions. ✅

If you want, I can also create a visual diagram showing PeckBirdy’s attack chain and backdoor modules for easier understanding. Do you want me to do that?

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: www.trendmicro.com
Extra Source Hub (Possible Sources for article):
https://www.quora.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2
Bing

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon