# PeckBirdy JScript C2 Framework Hides China-Aligned APT Infrastructure Inside a Casino-Site Network (CVE-2020-16040)

> China-aligned APT clusters have run the JScript-based PeckBirdy C2 framework since 2023 inside low-quality Chinese-language gambling sites, using fake browser-update lures and living-off-the-land execution to deploy backdoors such as HOLODONUT, MKDOOR, and GRAYRABBIT against Chinese gambling operators and, since July 2024, Asian government and education targets. Infoblox research published in September 2026 found PeckBirdy C2 domains embedded in a ~1.7 million-domain casino network whose hosting is laundered through compromised AWS, Microsoft, Cloudflare, and Google cloud accounts, with the same casino-site cover separately reused by North Korean money-laundering operations.

- **Published:** 2026-09-15T00:00:00Z
- **Last reviewed:** 2026-09-15T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2527
- **ID:** TL-2026-2527
- **Severity:** HIGH (CVSS 6.5)
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** Earth Lusca (China)
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2020-16040

## Description

PeckBirdy is a JScript-based command-and-control framework, in documented use by China-aligned threat clusters since 2023, engineered to run across a wide set of execution contexts -- web browsers, MSHTA, WScript, Classic ASP, Node.js, and .NET ScriptControl -- by detecting environment-specific objects (window, process, response, HTA APPLICATION tags) at runtime. Communications use AES encryption with Base64 encoding, keyed to a 32-character ATTACK_ID value embedded in each deployment's configuration, with a WebSocket-first, Adobe Flash TCP, then Comet (HTTP/AJAX) fallback chain. Victims are fingerprinted by hashing motherboard/drive identifiers (local contexts), a browser cookie prefixed Hm_lvt_, or a temporary file named ___unique_id___ in other runtimes.

Trend Micro's technical report (published 2026-01-26, first presented at HitCon in August 2025) documents two attributed campaigns. SHADOW-VOID-044, active since 2023, injects malicious scripts into Chinese-language gambling websites that serve fake Chrome update pages; the delivered payloads include a Chrome V8 exploit for CVE-2020-16040 and, via shared C2 infrastructure at center.myrnicrosoft.com, the DLL-sideloaded GRAYRABBIT backdoor attributed to UNC3569 (moderate-high confidence). Cobalt Strike samples in this cluster are signed with a code-signing certificate stolen from a South Korean gaming company, the same certificate previously observed in a 2021 BIOPASS RAT campaign linked to Earth Lusca (Aquatic Panda/RedHotel). A secondary infrastructure overlap (mkdmcdn.com, the HOLODONUT backdoor) connects the cluster to TheWizards.

SHADOW-EARTH-045, observed since July 2024, targets Asian government entities and private organizations, including a Philippine educational institution, via government website injection for credential harvesting and MSHTA-driven lateral movement. Its C2 IP, 47.238.184.9, is linked with low confidence to Earth Baxia and has separately surfaced in reporting on APT41 activity. This campaign's modular MKDOOR backdoor masquerades its C2 traffic as Microsoft support and Windows-activation pages and adds itself to the Microsoft Defender exclusion list; the HOLODONUT backdoor used alongside it is deployed in-memory via the open-source Donut loader after being fetched by the NEXLOAD downloader, and both PeckBirdy variants disable AMSI and ETW to evade endpoint telemetry.

Infoblox threat researcher Zach Edwards' follow-on investigation, reported by The Register on 2026-09-15, found PeckBirdy C2 domains (including vip311.cc, zzyud.com, and zenplay77-x.space) hidden inside a sprawling network of roughly 1.7 million low-quality Chinese-language gambling domains; just over 3% of Infoblox's enterprise customer base was observed resolving at least one PeckBirdy C2 domain. Operators launder hosting for both the casino network and the C2 infrastructure through compromised Amazon Web Services, Microsoft, Cloudflare, and Google cloud accounts. The same casino-site cover is independently exploited by North Korean money-laundering operations and other financially motivated actors running "scambling" (unwinnable gambling scam) sites, against a backdrop of an estimated $88.3 billion to $114.1 billion in 2025 online-scam losses across East and Southeast Asia.

## MITRE ATT&CK

- T1203 Exploitation for Client Execution
- T1204.002 Malicious File
- T1059.007 JavaScript
- T1574.001 DLL
- T1218.005 Mshta
- T1620 Reflective Code Loading
- T1685 Disable or Modify Tools
- T1027.002 Software Packing
- T1553.002 Code Signing
- T1036.005 Match Legitimate Resource Name or Location
- T1665 Hide Infrastructure
- T1140 Deobfuscate/Decode Files or Information
- T1071.001 Web Protocols
- T1573.001 Symmetric Cryptography
- T1583.001 Domains
- T1584.006 Web Services
- T1588.003 Code Signing Certificates

## Sources

- [Low-quality casino sites conceal 'highly dangerous' threat actors](https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652)
- [PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups](https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/peckbirdy-script-framework)
- [China-Linked Hackers Have Used the PeckBirdy JavaScript C2 Framework Since 2023](https://thehackernews.com/2026/01/china-linked-hackers-have-used.html)
- [PeckBirdy framework used by China-linked APTs targets gambling and government entities](https://www.scworld.com/brief/peckbirdy-framework-used-by-china-linked-apts-targets-gambling-and-government-entities)
- [PeckBirdy Hackers Abuse LOLBins Across Environments to Deploy Advanced Malware](https://gbhackers.com/peckbirdy-hackers/)
- [PeckBirdy C2 Framework – China-Aligned Modular Espionage Campaigns](https://northerntribesecurity.blogspot.com/2026/01/peckbirdy-c2-framework-china-aligned.html)
- [CVE-2020-16040 Detail](https://nvd.nist.gov/vuln/detail/CVE-2020-16040)
- [Stable Channel Update for Desktop](https://chromereleases.googleblog.com/2020/12/stable-channel-update-for-desktop.html)
- [Chrome bug 1150649 (V8 SimplifiedLowering integer overflow)](https://crbug.com/1150649)
- [Google Chrome 86.0.4240 V8 Remote Code Execution](http://packetstormsecurity.com/files/162144/Google-Chrome-SimplfiedLowering-Integer-Overflow.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2527
