Provide current and historical ownership information on domains / IPs. Identify all connections between domains, registrants, registrars, and DNS servers.
Trend Micro recently reported on PeckBirdy, a JavaScript-based command-and-control (C&C) framework used by China-aligned APT actors since 2023. Designed to operate across multiple environments, PeckBirdy enables flexible deployment and has been linked to campaigns involving modular backdoors such as HOLODONUT and MKDOOR, along with Cobalt Strike payloads, stolen code-signing certificates, and exploitation of CVE-2020-16040.
The researchers identified 36 network IoCs1 tied to the activity. After extracting unique domains from the subdomains flagged as IoCs, we analyzed 56 IoCs in total. Using our homegrown tools to investigate the threat, we uncovered these findings: