Skip to main content
Mallory
🇨🇳 CN1 malware familyExploits CVEs in the wild

SHADOW-EARTH-045

Also known asshadow_earth_045

SHADOW-EARTH-045 is a temporary intrusion set label used by Trend Micro for a PeckBirdy (aka PickBirdy) JScript-based command-and-control framework campaign first observed in July 2024. The activity is assessed as likely China-aligned, but specific attribution is uncertain; Trend Micro notes only a low-confidence link to the actor it tracks as Earth Baxia based on infrastructure overlap (including downloads from 47.238.184.9, described as previously linked to Earth Baxia, and mention of shared PeckBirdy domain/IP in reporting on attacks against an African government IT organization). Operations attributed to SHADOW-EARTH-045 targeted Asian government entities and private organizations, including a Philippine educational institution (observed July 2024). Tactics described include website injection/watering-hole style delivery: injecting PeckBirdy links into government websites (including at least one government system login page) to deliver scripts assessed as credential-harvesting. Execution and access methods include living-off-the-land and script-host abuse: use of MSHTA to retrieve content from github.githubassets.net to launch PeckBirdy, and use of a custom .NET executable leveraging the legacy ScriptControl component to trigger PeckBirdy in another case. PeckBirdy’s design (dynamically generated/runtime-injected JavaScript with limited file artifacts) is highlighted as complicating detection. Associated tooling/capabilities mentioned in the reporting include use of PeckBirdy as a remote access channel for lateral movement, and delivery/association with modular backdoors including MKDOOR and HOLODONUT; the content also states SHADOW-EARTH-045 used GRAYRABBIT and HOLODONUT in the broader PeckBirdy activity context, with HOLODONUT assessed as likely linked to WizardNet used by an APT referred to as TheWizard.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Commercial & Professional Services

Where they target

Geographies tied to known operations.

  • 🇵🇭 Philippines

Where they're from

Attributed origin per open-source reporting.

  • CN
MITRE ATT&CK

Tradecraft

7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

4 of 15 tactics8 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1189
Drive-by Compromise
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1203
Exploitation for Client Execution
TA0005
Stealth
1 technique
T1218
System Binary Proxy Execution
T1218.005
Mshta
TA0011
Command and Control
2 techniques
T1105
Ingress Tool Transfer
T1573
Encrypted Channel
ACTIVITY FEED

Recent activity

4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

dark readingNews
Jan 30, 2026
Chinese APTs Hacking Asian Orgs With High-End Malware

Trend Micro-tracked China-linked activity cluster (low-confidence linkage to Earth Baxia) using the PeckBirdy C2 framework for espionage-oriented intrusions against Asian private organizations and government-affiliated entities, leveraging multiple execution environments and LOLBins for flexible deployment.

Read more
dark readingNews
Jan 28, 2026
China-Backed 'PeckBirdy' Takes Flight for Cross-Platform Attacks

Campaign/activity cluster (assessed China-aligned) targeting Asian government entities (and a Philippine educational institution) using web injection to deliver PeckBirdy for credential harvesting and remote access/lateral movement; associated with GrayRabbit and newly identified HoloDonut backdoor; also used MSHTA and a .NET launcher leveraging ScriptControl.

Read more
the hacker newsNews
Jan 27, 2026
China-Linked Hackers Have Used the PeckBirdy JavaScript C2 Framework Since 2023

China-aligned intrusion set observed from July 2024 targeting Asian government entities and private organizations (including an educational institution in the Philippines) by injecting PeckBirdy links into government websites, likely for credential harvesting and as a remote access channel; associated infrastructure includes an IP previously linked to Earth Baxia and APT41.

Read more
trend micro researchNews
Jan 26, 2026
PeckBirdy: A Versatile Script Framework for LOLBins Exploitation Used by China-aligned Threat Groups | Trend Micro (US)

Temporary intrusion set observed targeting a Philippine educational institution; used MSHTA to fetch content from githubassets infrastructure to launch PeckBirdy on a compromised IIS server. Low-confidence linkage to Earth Baxia based on shared IP/domain infrastructure.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping7

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal1

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.

SHADOW-EARTH-045 | Mallory