China-Aligned APTs Use PeckBirdy C&C Framework in Multi-Vector Attacks, Exploiting Stolen Certificates
Since 2023, the malware framework PeckBirdy has been identified as a primary tool used by hacking groups aligned with Chinese interests. This JavaScript-based command-and-control platform supports operations across various system environments, providing…
Since 2023, the malware framework PeckBirdy has been identified as a primary tool used by hacking groups aligned with Chinese interests. This JavaScript-based command-and-control platform supports operations across various system environments, providing attackers significant flexibility.
The framework primarily targets the gambling industry and government organizations in Asia. PeckBirdy embeds malicious code into frequently visited websites. When users visit these compromised pages, hidden scripts activate the PeckBirdy framework silently in the background.
PeckBirdy deceives users by displaying fake browser update pages, leading them to download what appears to be legitimate software patches. In reality, these downloads are sophisticated backdoor programs granting attackers full system control.
The malware has been observed in two distinct campaigns: SHADOW-VOID-044 and SHADOW-EARTH-045. Trend Micro analysts identified PeckBirdy after discovering its deployment on compromised Chinese gambling websites. This research unveiled the full capabilities of the framework and its operational infrastructure across multiple attack phases.
Since 2023, the malware framework PeckBirdy has been identified as a primary tool used by hacking groups aligned with Chinese interests.
Infection Mechanism and Persistence Strategy
PeckBirdy employs a blend of outdated scripting languages and modern attack techniques. Developed with JScript, a legacy Microsoft scripting language, it ensures compatibility with most Windows systems without triggering security alerts. This approach allows attackers to bypass security tools focused on more recent threats.
Upon installation, PeckBirdy creates a unique identifier for each infected computer by extracting hardware information, encrypting it, and storing it in a hidden file. This identifier helps attackers recognize the same victim in future incursions.
PeckBirdy maintains persistent access by communicating with command servers through an encrypted protocol, continuously checking for new instructions while avoiding detection by security software .
The framework is particularly dangerous due to its deployment of secondary backdoors like HOLODONUT and MKDOOR. These modules execute arbitrary commands, steal credentials, and establish reverse shell connections, granting attackers complete remote access to compromised networks.
Organizations are advised to implement comprehensive network monitoring and conduct employee training on social engineering to mitigate these threats.
Based on reporting by Cyber Security News.
