TF-MAL-js.peckbirdy
📛 Threat Title
Malware family: PeckBirdy
Description
ThreatFox malware family `js.peckbirdy`. Printable name: PeckBirdy.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.peckbirdy
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.peckbirdy
IOC database
- Type
- domain
- Value
js.peckbirdy- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.peckbirdy
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.peckbirdy
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bearyangry.com
Mitigation Steps Immediate Actions - Short‑Term Fixes Block known PeckBirdy C&C domains and IPs using firewall or DNS filtering. Trend Micro's Vision One provides updated IOCs for the SHADOW campaigns. Disable or restrict execution of mshta.exe, wscript.exe, and ScriptControl on endpoints that do not require them. Group Policy can enforce ...
-
web:cyberpress.org
China-aligned hackers have weaponized a JScript-based command-and-control (C&C) framework called PeckBirdy since 2023. This tool abuses living-off-the-land binaries (LOLBins) like MSHTA and WScript to run across browsers, servers, and local machines.
-
web:cybersecsentinel.com
Overview PeckBirdy is a highly adaptable JScript based command and control framework attributed to China aligned advanced persistent threat activity. While active since at least 2023, its full technical scope and strategic significance were first comprehensively documented in January 2026. Unlike conventional malware families that rely on compiled executables, PeckBirdy leverages legacy ...
-
web:cybersecuritynews.com
Since 2023, a dangerous malware framework called PeckBirdy has emerged as a primary weapon used by Chinese-aligned hacking groups. This JavaScript-based tool serves as a command-and-control platform designed to work across multiple system environments, giving attackers remarkable flexibility in how they deploy their attacks.
-
web:iplogger.org
China-backed 'PeckBirdy' group uses JScript C2 and new backdoors in cross-platform attacks targeting gambling sites and governments.
-
web:malpedia.caad.fkie.fraunhofer.de
According to Trend Micro, PeckBirdy is a script-based framework which, while possessing advanced capabilities, is implemented using JScript, an old script language. This is to ensure that the framework could be launched across different execution environments via LOLBins (Living off the land binaries). This flexibility allowed to use PeckBirdy in various kill chain stages, including being used ...
-
web:socprime.com
China-aligned APTs use PeckBirdy JScript C2 across MSHTA/WScript/NodeJS to deliver HOLODONUT and MKDOOR, with WebSocket/HTTP channels.
-
web:thehackernews.com
Experts details PeckBirdy , a JavaScript C2 framework used since 2023 by China-aligned attackers to spread malware via fake updates & web injections.
-
web:www.darkreading.com
China-Backed 'PeckBirdy' Takes Flight for Cross-Platform Attacks In two separate campaigns, attackers used the JScript C2 framework to target Chinese gambling websites and Asian government ...
-
web:www.trendmicro.com
PeckBirdy is a sophisticated JScript-based C&C framework used by China-aligned APT groups to exploit LOLBins across multiple environments, delivering advanced backdoors to target gambling industries and Asian government entities.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.