Threat reportMalwareTL-2026-2527
PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network (CVE-2020-16040)
PeckBirdy JScript C2 Framework Hides China-Aligned APT (TL-2026-2527), also tracked as PeckBirdy, is a high-severity malware campaign scored CVSS 6.5, first published 2026-09-15. It is attributed to Earth Lusca (China) with medium confidence, affects Google Chrome, references 1 CVE (CVE-2020-16040), maps to 17 MITRE ATT&CK techniques (T1027.002, T1036.005, T1059.007), and is covered by 9 detection rules and 25 indicators of compromise.
- CVSS
- 6.5/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 17MITRE ATT&CK
- Actors
- 2Earth Lusca
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-2527
- Threat ID
- TL-2026-2527
- Also known as
- PeckBirdy, SHADOW-VOID-044, SHADOW-EARTH-045
- Severity
- HIGH
- CVSS
- 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- Earth Lusca, Earth Baxia
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- gambling, government administration, education
- Target regions
- china, Southeast Asia, East Asia, philippines
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in PeckBirdy JScript C2 Framework Hides China-Aligned APT
Malware and tooling: Cobalt Strike, GRAYRABBIT, HOLODONUT, MKDOOR, NEXLOAD, PeckBirdy, Cobalt Strike, Donut - S0695
How PeckBirdy JScript C2 Framework Hides China-Aligned APT works
China-aligned APT clusters have run the JScript-based PeckBirdy C2 framework since 2023 inside low-quality Chinese-language gambling sites, using fake browser-update lures and living-off-the-land execution to deploy backdoors such as HOLODONUT, MKDOOR, and GRAYRABBIT against Chinese gambling operators and, since July 2024, Asian government and education targets. Infoblox research published in September 2026 found PeckBirdy C2 domains embedded in a ~1.7 million-domain casino network whose hosting is laundered through compromised AWS, Microsoft, Cloudflare, and Google cloud accounts, with the same casino-site cover separately reused by North Korean money-laundering operations.
PeckBirdy is a JScript-based command-and-control framework, in documented use by China-aligned threat clusters since 2023, engineered to run across a wide set of execution contexts -- web browsers, MSHTA, WScript, Classic ASP, Node.js, and .NET ScriptControl -- by detecting environment-specific objects (window, process, response, HTA APPLICATION tags) at runtime. Communications use AES encryption with Base64 encoding, keyed to a 32-character ATTACK_ID value embedded in each deployment's configuration, with a WebSocket-first, Adobe Flash TCP, then Comet (HTTP/AJAX) fallback chain. Victims are fingerprinted by hashing motherboard/drive identifiers (local contexts), a browser cookie prefixed Hm_lvt_, or a temporary file named ___unique_id___ in other runtimes.
Trend Micro's technical report (published 2026-01-26, first presented at HitCon in August 2025) documents two attributed campaigns. SHADOW-VOID-044, active since 2023, injects malicious scripts into Chinese-language gambling websites that serve fake Chrome update pages; the delivered payloads include a Chrome V8 exploit for CVE-2020-16040 and, via shared C2 infrastructure at center.myrnicrosoft.com, the DLL-sideloaded GRAYRABBIT backdoor attributed to UNC3569 (moderate-high confidence). Cobalt Strike samples in this cluster are signed with a code-signing certificate stolen from a South Korean gaming company, the same certificate previously observed in a 2021 BIOPASS RAT campaign linked to Earth Lusca (Aquatic Panda/RedHotel). A secondary infrastructure overlap (mkdmcdn.com, the HOLODONUT backdoor) connects the cluster to TheWizards.
SHADOW-EARTH-045, observed since July 2024, targets Asian government entities and private organizations, including a Philippine educational institution, via government website injection for credential harvesting and MSHTA-driven lateral movement. Its C2 IP, 47.238.184.9, is linked with low confidence to Earth Baxia and has separately surfaced in reporting on APT41 activity. This campaign's modular MKDOOR backdoor masquerades its C2 traffic as Microsoft support and Windows-activation pages and adds itself to the Microsoft Defender exclusion list; the HOLODONUT backdoor used alongside it is deployed in-memory via the open-source Donut loader after being fetched by the NEXLOAD downloader, and both PeckBirdy variants disable AMSI and ETW to evade endpoint telemetry.
Infoblox threat researcher Zach Edwards' follow-on investigation, reported by The Register on 2026-09-15, found PeckBirdy C2 domains (including vip311.cc, zzyud.com, and zenplay77-x.space) hidden inside a sprawling network of roughly 1.7 million low-quality Chinese-language gambling domains; just over 3% of Infoblox's enterprise customer base was observed resolving at least one PeckBirdy C2 domain. Operators launder hosting for both the casino network and the C2 infrastructure through compromised Amazon Web Services, Microsoft, Cloudflare, and Google cloud accounts. The same casino-site cover is independently exploited by North Korean money-laundering operations and other financially motivated actors running "scambling" (unwinnable gambling scam) sites, against a backdrop of an estimated $88.3 billion to $114.1 billion in 2025 online-scam losses across East and Southeast Asia.
MITRE ATT&CK techniques used in TL-2026-2527
Defense Evasion
T1027.002 Software Packing; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1218.005 Mshta; T1620 Reflective Code Loading
Execution
T1059.007 JavaScript; T1203 Exploitation for Client Execution; T1204.002 Malicious File
Command and Control
T1071.001 Web Protocols; T1573.001 Symmetric Cryptography
defense-impairment
T1553.002 Code Signing; T1685 Disable or Modify Tools
stealth
Resource Development
T1583.001 Domains; T1584.006 Web Services; T1588.003 Code Signing Certificates
command-and-control
Affected products and versions in PeckBirdy JScript C2 Framework Hides China-Aligned APT
- Google — Chrome
Vulnerable versions: < 87.0.4280.88
Fixed in: 87.0.4280.88
Remediation for PeckBirdy JScript C2 Framework Hides China-Aligned APT
Patches
- Update Google Chrome and Chromium-based browsers to version 87.0.4280.88 or later (CVE-2020-16040)
Immediate actions
- Block known PeckBirdy C2 domains (vip311.cc, zzyud.com, zenplay77-x.space, center.myrnicrosoft.com, oss-cdn.com, mkdmcdn.com, github.githubassets.net) and IPs (47.238.219.111, 47.238.184.9) at DNS/perimeter
- Alert on and block mshta.exe or wscript.exe processes spawned by a browser process
- Audit AWS, Microsoft, Cloudflare, and Google cloud account access logs for anomalous resource creation consistent with infrastructure laundering
Workarounds
- Enforce application allowlisting to prevent HTA/JScript payloads from invoking mshta.exe or wscript.exe
- Block code execution from browser-download temp directories via ASR rules
Longer-term hardening
- Deploy EDR with behavioral detection tuned for LOLBin abuse (mshta, wscript, cscript) and reflective in-memory .NET loading (Donut)
- Monitor for AMSI/ETW-disabling API calls and unauthorized additions to Microsoft Defender exclusion lists
- Apply DNS threat-intelligence feeds covering low-reputation Chinese-language gambling domain clusters
CVEs associated with PeckBirdy JScript C2 Framework Hides China-Aligned APT
Weaknesses (CWE) in PeckBirdy JScript C2 Framework Hides China-Aligned APT
Timeline of PeckBirdy JScript C2 Framework Hides China-Aligned APT
- Google patches CVE-2020-16040 (V8 insufficient data validation) in Chrome 87.0.4280.88; the flaw is later weaponized by PeckBirdy operators.
- A code-signing certificate stolen from a South Korean gaming company, later reused to sign Cobalt Strike in the SHADOW-VOID-044 cluster, first appears in a BIOPASS RAT campaign linked to Earth Lusca.
- The PeckBirdy JScript C2 framework is first observed in the SHADOW-VOID-044 campaign, injected into Chinese-language gambling websites to serve fake Chrome update lures.
- SHADOW-EARTH-045 activity begins, targeting Asian government entities and private organizations, including a Philippine educational institution, via website injection and MSHTA-driven lateral movement.
- Trend Micro researchers first present PeckBirdy findings at the HitCon security conference.
- The Hacker News, SC Media, GBHackers, and other outlets publish coverage summarizing the PeckBirdy report and its China-aligned attribution.
- Trend Micro publishes the full technical report on the PeckBirdy framework, detailing SHADOW-VOID-044, SHADOW-EARTH-045, and associated HOLODONUT/MKDOOR/GRAYRABBIT malware.
- The Register publishes coverage of the Infoblox findings, additionally linking the same casino-site infrastructure to North Korean money-laundering operations and other cybercriminal 'scambling' schemes.
- Infoblox researcher Zach Edwards reports PeckBirdy C2 domains hidden inside a network of roughly 1.7 million low-quality Chinese-language casino sites, with over 3% of Infoblox enterprise customers observed resolving a PeckBirdy C2 domain, and hosting laundered through compromised AWS, Microsoft, Cloudflare, and Google cloud accounts.
Sources cited for PeckBirdy JScript C2 Framework Hides China-Aligned APT
- Low-quality casino sites conceal 'highly dangerous' threat actors
- PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups
- China-Linked Hackers Have Used the PeckBirdy JavaScript C2 Framework Since 2023
- PeckBirdy framework used by China-linked APTs targets gambling and government entities
- PeckBirdy Hackers Abuse LOLBins Across Environments to Deploy Advanced Malware
- PeckBirdy C2 Framework – China-Aligned Modular Espionage Campaigns
- CVE-2020-16040 Detail
- Stable Channel Update for Desktop
- Chrome bug 1150649 (V8 SimplifiedLowering integer overflow)
- Google Chrome 86.0.4240 V8 Remote Code Execution
Detection coverage for TL-2026-2527
As of 2026-09-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2527 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.