PeckBirdy JavaScript Framework Sparks Security Concerns for Global Organizations Now

PeckBirdy JavaScript Framework Sparks Security Concerns for Global Organizations Now

Cybersecurity analysts uncovered PeckBirdy, a versatile JScript framework used by APT groups since 2023 to target Asian gambling sectors and government sites, raising serious security concerns.

NeboAI I summarize the news with data, figures and context
IN 30 SECONDS

IN 1 SENTENCE

SENTIMENT
Neutral

𒀭
NeboAI is working, please wait...
Preparing detailed analysis
Quick summary completed
Extracting data, figures and quotes...
Identifying key players and context
DETAILED ANALYSIS
SHARE

NeboAI produces automated editions of journalistic texts in the form of summaries and analyses. Its experimental results are based on artificial intelligence. As an AI edition, texts may occasionally contain errors, omissions, incorrect data relationships and other unforeseen inaccuracies. We recommend verifying the content.

In 2023, cybersecurity experts identified a JScript-based command-and-control framework named PeckBirdy, linked to China-aligned APT actors, which targets various sectors including the gambling industry and government entities in Asia. According to Trend Micro, this framework has been utilized in attacks against both private organizations and government websites, leading to the development of two operational clusters, tracked as SHADOW-VOID-044 and SHADOW-EARTH-045.

The SHADOW-VOID-044 campaign, notable for injecting malicious scripts into Chinese gambling websites, aims to trick users into downloading fake software updates for Google Chrome, thereby deploying malware. Conversely, SHADOW-EARTH-045, first noted in July 2024, specifically targets a Philippine educational institution and other government entities by embedding PeckBirdy links into their websites, likely for credential harvesting.

Researchers Ted Lee and Joseph C Chen emphasized the framework’s adaptability, which allows it to function across various environments such as web browsers and .NET. The attackers have also created a .NET executable to enhance the deployment of PeckBirdy, showcasing its capability to serve multiple malicious purposes.

Want to read the full article? Access the original article with all the details.
Read Original Article
TL;DR

This article is an original summary for informational purposes. Image credits and full coverage at the original source. · View Content Policy

Editorial
Editorial Staff

Our editorial team works around the clock to bring you the latest tech news, trends, and insights from the industry. We cover everything from artificial intelligence breakthroughs to startup funding rounds, gadget launches, and cybersecurity threats. Our mission is to keep you informed with accurate, timely, and relevant technology coverage.

Press Enter to search or ESC to close