s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-js.peckbirdy

📛 Threat Title

Malware family: PeckBirdy

Category: PeckBirdy First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.peckbirdy`. Printable name: PeckBirdy.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain js.peckbirdy VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.peckbirdy

IOC database

Type
domain
Value
js.peckbirdy
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-js.peckbirdy

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.peckbirdy

References (1)

Remediations (10)

  • web:bearyangry.com

    Mitigation Steps Immediate Actions - Short‑Term Fixes Block known PeckBirdy C&C domains and IPs using firewall or DNS filtering. Trend Micro's Vision One provides updated IOCs for the SHADOW campaigns. Disable or restrict execution of mshta.exe, wscript.exe, and ScriptControl on endpoints that do not require them. Group Policy can enforce ...

  • web:cyberpress.org

    China-aligned hackers have weaponized a JScript-based command-and-control (C&C) framework called PeckBirdy since 2023. This tool abuses living-off-the-land binaries (LOLBins) like MSHTA and WScript to run across browsers, servers, and local machines.

  • web:cybersecsentinel.com

    Overview PeckBirdy is a highly adaptable JScript based command and control framework attributed to China aligned advanced persistent threat activity. While active since at least 2023, its full technical scope and strategic significance were first comprehensively documented in January 2026. Unlike conventional malware families that rely on compiled executables, PeckBirdy leverages legacy ...

  • web:cybersecuritynews.com

    Since 2023, a dangerous malware framework called PeckBirdy has emerged as a primary weapon used by Chinese-aligned hacking groups. This JavaScript-based tool serves as a command-and-control platform designed to work across multiple system environments, giving attackers remarkable flexibility in how they deploy their attacks.

  • web:iplogger.org

    China-backed 'PeckBirdy' group uses JScript C2 and new backdoors in cross-platform attacks targeting gambling sites and governments.

  • web:malpedia.caad.fkie.fraunhofer.de

    According to Trend Micro, PeckBirdy is a script-based framework which, while possessing advanced capabilities, is implemented using JScript, an old script language. This is to ensure that the framework could be launched across different execution environments via LOLBins (Living off the land binaries). This flexibility allowed to use PeckBirdy in various kill chain stages, including being used ...

  • web:socprime.com

    China-aligned APTs use PeckBirdy JScript C2 across MSHTA/WScript/NodeJS to deliver HOLODONUT and MKDOOR, with WebSocket/HTTP channels.

  • web:thehackernews.com

    Experts details PeckBirdy , a JavaScript C2 framework used since 2023 by China-aligned attackers to spread malware via fake updates & web injections.

  • web:www.darkreading.com

    China-Backed 'PeckBirdy' Takes Flight for Cross-Platform Attacks In two separate campaigns, attackers used the JScript C2 framework to target Chinese gambling websites and Asian government ...

  • web:www.trendmicro.com

    PeckBirdy is a sophisticated JScript-based C&C framework used by China-aligned APT groups to exploit LOLBins across multiple environments, delivering advanced backdoors to target gambling industries and Asian government entities.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.