{"id":60069,"date":"2026-01-26T00:00:00","date_gmt":"2026-01-26T00:00:00","guid":{"rendered":"urn:uuid:5265919b-48a6-cabb-22d6-2dfda1459765"},"modified":"2026-01-26T00:00:00","modified_gmt":"2026-01-26T00:00:00","slug":"peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/","title":{"rendered":"PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/peckbirdy-976:Large?qlt=80\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/thumbnails\/26\/peckbirdy-976.png\" class=\"ff-og-image-inserted\"><\/div>\n<p>We discovered two threat campaigns that used &nbsp;PeckBirdy in their operations. Based on victimology and the tools, tactics, and procedures (TTPs) used in the respective campaigns, we attributed them under two temporary intrusion sets: SHADOW-VOID-044 and SHADOW-EARTH-045. Our investigation revealed that these two campaigns could be linked to different China-aligned APT actors.<\/p>\n<p>In the case of SHADOW-VOID-044, we noticed the GRAYRABBIT backdoor (previously reported to be utilized by <a href=\"https:\/\/www.virusbulletin.com\/uploads\/pdf\/conference\/vb2024\/papers\/Down-the-GRAYRABBIT-hole-exposing-UNC3569-and-its-modus-operandi.pdf\">UNC3569<\/a>) was hosted on a server (<i>47[.]238[.]219[.]111<\/i>) operated by this campaign. The GRAYRABBIT sample we observed was slightly different, using a DLL sideloading technique combined with the <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/api\/rpcdce\/nf-rpcdce-uuidfromstringa\">UuidFromStringA<\/a> function of PowerShell to read, decode, and execute the backdoor payload. Despite the different execution methods, the C&amp;C server center[.]myrnicrosoft[.]com was the same as the C&amp;C domain used by UNC3569. In addition, both SHADOW-VOID-044 and UNC3569 targeted the Chinese gambling industry. These findings give us a moderate to high level of confidence to attribute this campaign to UNC3569.<\/p>\n<p>We also discovered that SHADOW-VOID-044 used the HOLODONUT backdoor, which is likely linked to another backdoor, WizardNet, previously reported being used by an APT group called <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/thewizards-apt-group-slaac-spoofing-adversary-in-the-middle-attacks\/\">TheWizard<\/a>. Interestingly, some of the HOLODONUT samples used by SHADOW-VOID-044 connected to the same C&amp;C server (<i>mkdmcdn[.]com<\/i>), which is the same used by TheWizard. While we didn\u2019t see any additional connections between Campaign Alpha and TheWizard, it\u2019s worth noting that TheWizard also used the DarkNimbus backdoor which was developed by the <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/l\/earth-minotaur.html\">Earth Minotaur<\/a> threat actor we discussed in a previous blog entry.<\/p>\n<p>Another discovery during our research was a Cobalt Strike sample (SHA256: 162cc325ab7b6e70edb6f4d0bc0e52130c56903f) hosted on the SHADOW-VOID-044 server <i>oss-cdn[.]com<\/i>. We discovered that this sample was signed using a certificate (thumbprint, SHA1: bbd2b9b87f968ed88210d4261a1fe30711e8365b) stolen from a South Korean gaming company. This certificate was also used in the <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/g\/biopass-rat-new-malware-sniffs-victims-via-live-streaming.html\">BIOPASS RAT<\/a> campaign that we also reported on.<\/p>\n<p>Based on our findings, both BIOPASS RAT and MKDOOR employ the same technique: opening an HTTP server on a high-numbered port on the local host to listen. This is to allow a watering hole attack script to scan for the presence of the port on the local host and determine whether the victim has been infected with the backdoor. The BIOPASS RAT campaign is linked to another threat actor, <a href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/22\/a\/earth-lusca-employs-sophisticated-infrastructure-varied-tools-and-techniques\/technical-brief-delving-deep-an-analysis-of-earth-lusca-operations.pdf\">Earth Lusca<\/a>.<\/p>\n<p>For SHADOW-EARTH-045, we observed malicious activities targeting a Philippine educational institution in July 2024. The threat actor executed an MSHTA command connecting to <i>github[.]githubassets[.]net<\/i> to launch PeckBirdy on a compromised Internet Information Services (IIS) server. The threat actor also simultaneously downloaded files from <i>47[.]238[.]184[.]9<\/i>, an IP address has been previously linked to <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/24\/i\/earth-baxia-spear-phishing-and-geoserver-exploit.html\">Earth Baxia<\/a>. &nbsp;Note that the attribution linking SHADOW-EARTH-045 to Earth Baxia remains low confidence for now. However, it\u2019s worth noting that the same PeckBirdy domain and the IP address used was also mentioned in another <a href=\"https:\/\/securelist.com\/apt41-in-africa\/116986\/\">report<\/a> on attacks against an African government IT organization.<\/p>\n<p>This report outlines two campaigns that highlight the growing sophistication and adaptability of current China-align threat actors. These campaigns make use of a dynamic JavaScript framework, PickBirdy, to abuse living-off-the-land binaries and deliver modular backdoors such as MKDOOR and HOLODONUT. Detecting malicious JavaScript frameworks remains a significant challenge due to their use of dynamically generated, runtime-injected code and the absence of persistent file artifacts, enabling them to evade traditional endpoint security controls. In this environment, adaptability and continuous refinement of defensive strategies are no longer optional, but fundamental to maintaining operational integrity in an increasingly hostile digital landscape.<\/p>\n<p><span class=\"body-subhead-title\">Proactive security with TrendAI Vision One\u2122<\/span><\/p>\n<p><a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/one-platform.html\">TrendAI Vision One\u2122<\/a> is the industry-leading AI cybersecurity platform that centralizes cyber risk exposure management, security operations, and robust layered protection.<\/p>\n<p><a href=\"https:\/\/www.trendmicro.com\/en_us\/business\/products\/threat-intelligence.html\">TrendAI Vision One\u2122 Threat Intelligence Hub<\/a> provides the latest insights on emerging threats and threat actors, exclusive strategic reports from TrendAI\u2122 Research, and TrendAI Vision One\u2122 Threat Intelligence Feed in the TrendAI Vision One\u2122 platform.<\/p>\n<p><b>Emerging Threats:<\/b><\/p>\n<p><a href=\"https:\/\/portal.xdr.trendmicro.com\/index.html#\/app\/ti\/intelligence_insights?name=PeckBirdy%3A%20A%20Versatile%20Script%20Framework%20for%20LOLBins%20Exploitation%20Used%20by%20China-aligned%20Threat%20Groups\">PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups<\/a><\/p>\n<p><a href=\"https:\/\/portal.xdr.trendmicro.com\/index.html#\/app\/ti\/intelligence?intrusionSet=PeckBirdy%3A%20A%20Versatile%20Script%20Framework%20for%20LOLBins%20Exploitation%20Used%20by%20China-aligned%20Threat%20Groups\">PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups<\/a><\/p>\n<p><b>Threat actor profiles:<\/b><\/p>\n<p><span class=\"body-subhead-title\">Hunting Queries&nbsp;<\/span><\/p>\n<p>malName: (*MKDOOR* OR *HOLODONUT* OR *GRAYRABBIT* OR *PECKBIRDY*) AND eventName: MALWARE_DETECTION<\/p>\n<p>TrendAI Vision One\u2122 customers can use the Search App to match or hunt the malicious indicators mentioned in this blog post with data in their environment.&nbsp; &nbsp;&nbsp;<\/p>\n<p>More hunting queries are available for TrendAI Vision One\u2122 with Threat Intelligence Hub entitlement enabled.&nbsp;<\/p>\n<p>The indicators of compromise for this entry can be found <a href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/26\/a\/peckbirdy\/IOC-peckbirdy-2.txt\"><span class=\"bs-modal\">here<\/span><\/a>.<\/p>\n<p> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/26\/a\/peckbirdy-script-framework.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>PeckBirdy is a sophisticated JScript-based C&#038;C framework used by China-aligned APT groups to exploit LOLBins across multiple environments, delivering advanced backdoors to target gambling industries and Asian government entities. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":60070,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9546,9510,9509],"class_list":["post-60069","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-apttargeted-attacks","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-research"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2026-01-26T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/peckbirdy-976:Large?qlt=80\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups\",\"datePublished\":\"2026-01-26T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\\\/\"},\"wordCount\":773,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups.png\",\"keywords\":[\"Trend Micro Research : APT&amp;Targeted Attacks\",\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Research\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\\\/\",\"name\":\"PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups.png\",\"datePublished\":\"2026-01-26T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups.png\",\"width\":976,\"height\":533},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : APT&amp;Targeted Attacks\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-apttargeted-attacks\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/","og_locale":"en_US","og_type":"article","og_title":"PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2026-01-26T00:00:00+00:00","og_image":[{"url":"https:\/\/trendmicro.scene7.com\/is\/image\/trendmicro\/peckbirdy-976:Large?qlt=80","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups","datePublished":"2026-01-26T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/"},"wordCount":773,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/01\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups.png","keywords":["Trend Micro Research : APT&amp;Targeted Attacks","Trend Micro Research : Articles, News, Reports","Trend Micro Research : Research"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/","url":"https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/","name":"PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/01\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups.png","datePublished":"2026-01-26T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/01\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2026\/01\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups.png","width":976,"height":533},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/peckbirdy-a-versatile-script-framework-for-lolbins-exploitation-used-by-china-aligned-threat-groups\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : APT&amp;Targeted Attacks","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-apttargeted-attacks\/"},{"@type":"ListItem","position":3,"name":"PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/60069","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=60069"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/60069\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/60070"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=60069"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=60069"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=60069"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}