ZeroHour

Search: “Infoblox”

1 stories in the last 24h

PeckBirdy C2 Traffic Seen Across Enterprise Networks While Hiding Behind Casino Domainsnew

Infoblox and Trend Micro detail China-aligned actors hiding PeckBirdy JavaScript C2 behind Chinese casino domains, with over 3% of enterprise customers resolving malicious domains.

Infoblox telemetry found just over 3% of enterprise customers resolved at least one PeckBirdy C2 domain, including cache-mcp[.]com and mcp-source[.]online, indicating reach beyond the campaign's apparent Asian victim focus. Trend Micro links PeckBirdy, a JScript C2 framework active since 2023, to China-aligned campaigns targeting Chinese gambling organizations, Asian government entities, and private-sector organizations. Low-quality casino portals such as vip311[.]cc embed malicious JavaScript and WebSocket C2 endpoints that evade scanners, delivering tailored landing scripts for MSHTA, HTML, and WScript execution and abusing Windows LOLBins. Infoblox tracks roughly 1.7 million Chinese-language casino domains, with the FUNNULL CDN and Vigorish Viper clusters covering about 81% of that population.

GBHackers · 24m agoThreat actor in the wild 3 sources