SideWalk is a modular backdoor associated with China-linked espionage activity, most notably clusters tracked as SparklingGoblin and Grayfly, both of which have been linked by multiple vendors to the broader APT41/Winnti ecosystem. It has been observed in both Windows and Linux forms and appears to be closely related to the older CROSSWALK backdoor, with shared architectural and implementation traits suggesting common development lineage.
On Windows, SideWalk has been deployed through staged loader chains that use obfuscated .NET components, InstallUtil-based execution, encrypted shellcode, and process hollowing. It supports proxy-aware command-and-control, uses HTTP or HTTPS for communications, and has employed dead-drop resolution to obtain command-and-control information before contacting attacker infrastructure. The malware is designed as a multipurpose implant that can dynamically load additional modules from its controller.
On Linux, SideWalk has been documented as a sophisticated ELF backdoor and has also been referred to as StageClient or identified as overlapping with Specter RAT. Linux variants share substantial code and protocol similarities with the Windows implant, including ChaCha20-based encryption, configuration handling, victim fingerprinting, command structure, and dead-drop resolver logic. Linux builds have been observed with built-in modules for system information collection and scheduled remote command execution, and they communicate over web protocols using encrypted sessions.
Observed capabilities include collection of host and system information, execution of attacker-supplied commands, loading of additional functionality, and use of tunneling utilities to extend remote access into compromised environments. In some campaigns, operators paired SideWalk with web shells, credential-dumping tools, scheduled-task persistence, and proxying or tunneling mechanisms to support broader post-compromise operations.
Victimology linked to SideWalk spans academia, telecommunications, government, media, finance, IT, and other commercial sectors. Reported targeting has included organizations in East and Southeast Asia as well as victims in North America and Latin America. Delivery and deployment have been associated with exploitation of public-facing servers, including campaigns leveraging exposed enterprise services and, in 2024, exploitation of GeoServer vulnerability CVE-2024-36401 to deliver Linux variants across multiple CPU architectures.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ESET researchers have discovered a Linux variant of the SideWalk backdoor... We originally named this backdoor StageClient, but now refer to it simply as SideWalk Linux.
Symantec, part of Broadcom Software, has linked the recently discovered Sidewalk backdoor to the China-linked Grayfly espionage group.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
A characteristic of the recent campaign was that the group appeared to be particularly interested in attacking exposed Microsoft Exchange or MySQL servers. This suggests that the initial vector may be the exploit of multiple vulnerabilities against public-facing servers.
MITRE ATT&CK techniques ... Command and Control T1071.001 Application Layer Protocol: Web Protocols SideWalk Linux communicates via HTTPS with the C&C server.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A recently discovered backdoor used in Grayfly espionage campaigns, providing remote access within compromised networks and used after initial intrusion via exposed public-facing servers and web shells.
SideWalk is a modular backdoor used by various threat actors for persistent access and command execution on compromised systems. It was distributed via exploitation of the GeoServer vulnerability.
SideWalk (ScrambleCross) is a backdoor malware used by Chinese APTs for persistent access and command and control.
China-nexus custom backdoor family referenced via infrastructure artifacting (reused TLS certificate CN=AS.website) historically linked to SideWalk-related C2; not directly observed deployed in the described campaigns, but suggested by certificate reuse.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.