China-Aligned PeckBirdy Malware Hides C2 Infrastructure Inside Chinese-Language Casino and Adult Websites
Infoblox reports that China-aligned actors behind the PeckBirdy JScript C2 framework conceal command-and-control inside fake Chinese-language casino and adult websites, using service workers and WebSockets to evade conventional scanning; the campaign has been…
Infoblox researchers reported that China-aligned actors use PeckBirdy, a JScript-based command-and-control framework active since at least 2023, to deliver modular backdoors including MKDOOR and HOLODONUT against Asian government and gambling targets, extending Trend Micro's earlier findings on the framework. The C2 servers are hidden inside low-quality Chinese-language casino and adult websites; roughly 1.7 million illegal Chinese-language gambling domains provide camouflage that makes APT C2 look like ordinary consumer fraud. One decoy site, vip311[.]cc, embedded JavaScript linked to cache-mcp[.]com and registered a service worker connecting to mcp-source[.]online over WebSocket; mcp-source[.]online had zero VirusTotal detections at publication, while Infoblox observed VirusTotal detection coverage across the infrastructure ranging from 13 detections down to none. Fake browser-update prompts deliver backdoors capable of running commands, stealing credentials, and providing remote access. Just over 3% of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain, with education, IT, banking and financial services, and government organizations among the observed sectors in Asia. Infoblox advises that 3-10 distinct C2 lookups warrant incident-response investigation, that single-domain blocking is ineffective, and that defenders should correlate DNS, proxy, and browser telemetry. The two reports differ slightly in wording: GBHackers describes PeckBirdy as JScript-based and lists education, IT, banking and government as targeted sectors, while Cyber Security News calls it a JavaScript framework and adds financial services to the sector list.
- PeckBirdy is a JScript/JavaScript-based C2 framework used by China-aligned actors since at least 2023, delivering modular backdoors including MKDOOR and HOLODONUT (GBHackers notes it extends Trend Micro's earlier findings).
- C2 infrastructure is concealed inside low-quality Chinese-language casino and adult websites; roughly 1.7 million illegal Chinese-language gambling domains create camouflage.
- Decoy site vip311[.]cc embedded JavaScript linked to cache-mcp[.]com and registered a service worker connecting to mcp-source[.]online over WebSocket; service-worker persistence and WebSocket C2 can be missed by conventional web scanners…
- VirusTotal detection coverage ranged from 13 detections to none across the infrastructure; mcp-source[.]online had zero detections at publication time.
- Just over 3% of Infoblox enterprise customers resolved at least one PeckBirdy C2 domain.
- Targeted sectors in Asia include education, IT, banking and financial services, and government (GBHackers lists education, IT, banking and government; Cyber Security News adds financial services).
- Fake browser-update prompts delivered by the sites drop backdoors capable of running commands, stealing credentials, and providing remote access.
- Infoblox guidance: 3-10 distinct PeckBirdy C2 lookups warrant incident-response investigation; correlate DNS, proxy, and browser telemetry, as single-domain blocking is ineffective.
Coverage timelineoldest first · each row is one article
- · 17h agoChina-Aligned Hackers Hide PeckBirdy Malware C2 Inside Casino and Adult Websites
GBHackers· 62
Infoblox found China-aligned actors hiding PeckBirdy malware C2 inside fake Chinese-language casino and adult websites, evading security scans via service workers and WebSockets.
- · 14h agoHackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Cyber Security News· 63
Infoblox links China-aligned APT PeckBirdy C2 infrastructure hidden in casino and adult websites targeting Asian government, finance, IT, and education sectors.