SHADOW-EARTH-045
SHADOW-EARTH-045 is a temporary intrusion set label used by Trend Micro for a PeckBirdy (aka PickBirdy) JScript-based command-and-control framework campaign first observed in July 2024. The activity is assessed as likely China-aligned, but specific attribution is uncertain; Trend Micro notes only a low-confidence link to the actor it tracks as Earth Baxia based on infrastructure overlap (including downloads from 47.238.184.9, described as previously linked to Earth Baxia, and mention of shared PeckBirdy domain/IP in reporting on attacks against an African government IT organization). Operations attributed to SHADOW-EARTH-045 targeted Asian government entities and private organizations, including a Philippine educational institution (observed July 2024). Tactics described include website injection/watering-hole style delivery: injecting PeckBirdy links into government websites (including at least one government system login page) to deliver scripts assessed as credential-harvesting. Execution and access methods include living-off-the-land and script-host abuse: use of MSHTA to retrieve content from github.githubassets.net to launch PeckBirdy, and use of a custom .NET executable leveraging the legacy ScriptControl component to trigger PeckBirdy in another case. PeckBirdy’s design (dynamically generated/runtime-injected JavaScript with limited file artifacts) is highlighted as complicating detection. Associated tooling/capabilities mentioned in the reporting include use of PeckBirdy as a remote access channel for lateral movement, and delivery/association with modular backdoors including MKDOOR and HOLODONUT; the content also states SHADOW-EARTH-045 used GRAYRABBIT and HOLODONUT in the broader PeckBirdy activity context, with HOLODONUT assessed as likely linked to WizardNet used by an APT referred to as TheWizard.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Commercial & Professional Services
Where they target
Geographies tied to known operations.
- 🇵🇭 Philippines
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
1 malware family attributed to this actor across reporting.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trend Micro-tracked China-linked activity cluster (low-confidence linkage to Earth Baxia) using the PeckBirdy C2 framework for espionage-oriented intrusions against Asian private organizations and government-affiliated entities, leveraging multiple execution environments and LOLBins for flexible deployment.
Campaign/activity cluster (assessed China-aligned) targeting Asian government entities (and a Philippine educational institution) using web injection to deliver PeckBirdy for credential harvesting and remote access/lateral movement; associated with GrayRabbit and newly identified HoloDonut backdoor; also used MSHTA and a .NET launcher leveraging ScriptControl.
China-aligned intrusion set observed from July 2024 targeting Asian government entities and private organizations (including an educational institution in the Philippines) by injecting PeckBirdy links into government websites, likely for credential harvesting and as a remote access channel; associated infrastructure includes an IP previously linked to Earth Baxia and APT41.
Temporary intrusion set observed targeting a Philippine educational institution; used MSHTA to fetch content from githubassets infrastructure to launch PeckBirdy on a compromised IIS server. Low-confidence linkage to Earth Baxia based on shared IP/domain infrastructure.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.