PeckBirdy

Malware type
backdoor, rat, trojan
Family
Malware family
Profile updated
2026-07-07 14:33:57

Targeted industries: technology-and-telecommunications government-and-public-sector financial-services

Context

According to Trend Micro, PeckBirdy is a script-based framework which, while possessing advanced capabilities, is implemented using JScript, an old script language. This is to ensure that the framework could be launched across different execution environments via LOLBins (Living off the land binaries). This flexibility allowed to use PeckBirdy in various kill chain stages, including being used as a watering-hole control server during the initial attack phase, as a reverse shell server during the lateral movement phase, and as a C&C server during the backdoor phase.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Js.Peckbirdy (report)
  • Trend Micro — Peckbirdy Script Framework (report)

External references