Threat reportMalwareTL-2026-2527

PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network (CVE-2020-16040)

highACTIVE

PeckBirdy JScript C2 Framework Hides China-Aligned APT (TL-2026-2527), also tracked as PeckBirdy, is a high-severity malware campaign scored CVSS 6.5, first published 2026-09-15. It is attributed to Earth Lusca (China) with medium confidence, affects Google Chrome, references 1 CVE (CVE-2020-16040), maps to 17 MITRE ATT&CK techniques (T1027.002, T1036.005, T1059.007), and is covered by 9 detection rules and 25 indicators of compromise.

CVSS
6.5/10High
CVEs
1Referenced vulnerabilities
Techniques
17MITRE ATT&CK
Actors
2Earth Lusca
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-2527

Threat ID
TL-2026-2527
Also known as
PeckBirdy, SHADOW-VOID-044, SHADOW-EARTH-045
Severity
HIGH
CVSS
6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
Earth Lusca, Earth Baxia
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
ESPIONAGE
Target sectors
gambling, government administration, education
Target regions
china, Southeast Asia, East Asia, philippines
Detection rules
9
Indicators of compromise
25

Malware and tooling in PeckBirdy JScript C2 Framework Hides China-Aligned APT

Malware and tooling: Cobalt Strike, GRAYRABBIT, HOLODONUT, MKDOOR, NEXLOAD, PeckBirdy, Cobalt Strike, Donut - S0695

How PeckBirdy JScript C2 Framework Hides China-Aligned APT works

China-aligned APT clusters have run the JScript-based PeckBirdy C2 framework since 2023 inside low-quality Chinese-language gambling sites, using fake browser-update lures and living-off-the-land execution to deploy backdoors such as HOLODONUT, MKDOOR, and GRAYRABBIT against Chinese gambling operators and, since July 2024, Asian government and education targets. Infoblox research published in September 2026 found PeckBirdy C2 domains embedded in a ~1.7 million-domain casino network whose hosting is laundered through compromised AWS, Microsoft, Cloudflare, and Google cloud accounts, with the same casino-site cover separately reused by North Korean money-laundering operations.

PeckBirdy is a JScript-based command-and-control framework, in documented use by China-aligned threat clusters since 2023, engineered to run across a wide set of execution contexts -- web browsers, MSHTA, WScript, Classic ASP, Node.js, and .NET ScriptControl -- by detecting environment-specific objects (window, process, response, HTA APPLICATION tags) at runtime. Communications use AES encryption with Base64 encoding, keyed to a 32-character ATTACK_ID value embedded in each deployment's configuration, with a WebSocket-first, Adobe Flash TCP, then Comet (HTTP/AJAX) fallback chain. Victims are fingerprinted by hashing motherboard/drive identifiers (local contexts), a browser cookie prefixed Hm_lvt_, or a temporary file named ___unique_id___ in other runtimes.

Trend Micro's technical report (published 2026-01-26, first presented at HitCon in August 2025) documents two attributed campaigns. SHADOW-VOID-044, active since 2023, injects malicious scripts into Chinese-language gambling websites that serve fake Chrome update pages; the delivered payloads include a Chrome V8 exploit for CVE-2020-16040 and, via shared C2 infrastructure at center.myrnicrosoft.com, the DLL-sideloaded GRAYRABBIT backdoor attributed to UNC3569 (moderate-high confidence). Cobalt Strike samples in this cluster are signed with a code-signing certificate stolen from a South Korean gaming company, the same certificate previously observed in a 2021 BIOPASS RAT campaign linked to Earth Lusca (Aquatic Panda/RedHotel). A secondary infrastructure overlap (mkdmcdn.com, the HOLODONUT backdoor) connects the cluster to TheWizards.

SHADOW-EARTH-045, observed since July 2024, targets Asian government entities and private organizations, including a Philippine educational institution, via government website injection for credential harvesting and MSHTA-driven lateral movement. Its C2 IP, 47.238.184.9, is linked with low confidence to Earth Baxia and has separately surfaced in reporting on APT41 activity. This campaign's modular MKDOOR backdoor masquerades its C2 traffic as Microsoft support and Windows-activation pages and adds itself to the Microsoft Defender exclusion list; the HOLODONUT backdoor used alongside it is deployed in-memory via the open-source Donut loader after being fetched by the NEXLOAD downloader, and both PeckBirdy variants disable AMSI and ETW to evade endpoint telemetry.

Infoblox threat researcher Zach Edwards' follow-on investigation, reported by The Register on 2026-09-15, found PeckBirdy C2 domains (including vip311.cc, zzyud.com, and zenplay77-x.space) hidden inside a sprawling network of roughly 1.7 million low-quality Chinese-language gambling domains; just over 3% of Infoblox's enterprise customer base was observed resolving at least one PeckBirdy C2 domain. Operators launder hosting for both the casino network and the C2 infrastructure through compromised Amazon Web Services, Microsoft, Cloudflare, and Google cloud accounts. The same casino-site cover is independently exploited by North Korean money-laundering operations and other financially motivated actors running "scambling" (unwinnable gambling scam) sites, against a backdrop of an estimated $88.3 billion to $114.1 billion in 2025 online-scam losses across East and Southeast Asia.

MITRE ATT&CK techniques used in TL-2026-2527

Defense Evasion

T1027.002 Software Packing; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1218.005 Mshta; T1620 Reflective Code Loading

Execution

T1059.007 JavaScript; T1203 Exploitation for Client Execution; T1204.002 Malicious File

Command and Control

T1071.001 Web Protocols; T1573.001 Symmetric Cryptography

defense-impairment

T1553.002 Code Signing; T1685 Disable or Modify Tools

stealth

T1574.001 DLL

Resource Development

T1583.001 Domains; T1584.006 Web Services; T1588.003 Code Signing Certificates

command-and-control

T1665 Hide Infrastructure

Affected products and versions in PeckBirdy JScript C2 Framework Hides China-Aligned APT

  • Google — Chrome
    Vulnerable versions: < 87.0.4280.88
    Fixed in: 87.0.4280.88

Remediation for PeckBirdy JScript C2 Framework Hides China-Aligned APT

Patches

  • Update Google Chrome and Chromium-based browsers to version 87.0.4280.88 or later (CVE-2020-16040)

Immediate actions

  • Block known PeckBirdy C2 domains (vip311.cc, zzyud.com, zenplay77-x.space, center.myrnicrosoft.com, oss-cdn.com, mkdmcdn.com, github.githubassets.net) and IPs (47.238.219.111, 47.238.184.9) at DNS/perimeter
  • Alert on and block mshta.exe or wscript.exe processes spawned by a browser process
  • Audit AWS, Microsoft, Cloudflare, and Google cloud account access logs for anomalous resource creation consistent with infrastructure laundering

Workarounds

  • Enforce application allowlisting to prevent HTA/JScript payloads from invoking mshta.exe or wscript.exe
  • Block code execution from browser-download temp directories via ASR rules

Longer-term hardening

  • Deploy EDR with behavioral detection tuned for LOLBin abuse (mshta, wscript, cscript) and reflective in-memory .NET loading (Donut)
  • Monitor for AMSI/ETW-disabling API calls and unauthorized additions to Microsoft Defender exclusion lists
  • Apply DNS threat-intelligence feeds covering low-reputation Chinese-language gambling domain clusters

CVEs associated with PeckBirdy JScript C2 Framework Hides China-Aligned APT

CVE-2020-16040

Weaknesses (CWE) in PeckBirdy JScript C2 Framework Hides China-Aligned APT

CWE-20, CWE-190, CWE-787

Timeline of PeckBirdy JScript C2 Framework Hides China-Aligned APT

  • Google patches CVE-2020-16040 (V8 insufficient data validation) in Chrome 87.0.4280.88; the flaw is later weaponized by PeckBirdy operators.
  • A code-signing certificate stolen from a South Korean gaming company, later reused to sign Cobalt Strike in the SHADOW-VOID-044 cluster, first appears in a BIOPASS RAT campaign linked to Earth Lusca.
  • The PeckBirdy JScript C2 framework is first observed in the SHADOW-VOID-044 campaign, injected into Chinese-language gambling websites to serve fake Chrome update lures.
  • SHADOW-EARTH-045 activity begins, targeting Asian government entities and private organizations, including a Philippine educational institution, via website injection and MSHTA-driven lateral movement.
  • Trend Micro researchers first present PeckBirdy findings at the HitCon security conference.
  • The Hacker News, SC Media, GBHackers, and other outlets publish coverage summarizing the PeckBirdy report and its China-aligned attribution.
  • Trend Micro publishes the full technical report on the PeckBirdy framework, detailing SHADOW-VOID-044, SHADOW-EARTH-045, and associated HOLODONUT/MKDOOR/GRAYRABBIT malware.
  • The Register publishes coverage of the Infoblox findings, additionally linking the same casino-site infrastructure to North Korean money-laundering operations and other cybercriminal 'scambling' schemes.
  • Infoblox researcher Zach Edwards reports PeckBirdy C2 domains hidden inside a network of roughly 1.7 million low-quality Chinese-language casino sites, with over 3% of Infoblox enterprise customers observed resolving a PeckBirdy C2 domain, and hosting laundered through compromised AWS, Microsoft, Cloudflare, and Google cloud accounts.

Sources cited for PeckBirdy JScript C2 Framework Hides China-Aligned APT

Detection coverage for TL-2026-2527

As of 2026-09-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2527 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats