Crosswalk
Crosswalk is a modular backdoor associated with the China-linked threat ecosystem around APT41 and related clusters. The provided reporting explicitly attributes CROSSWALK to APT41, describes it as a primary backdoor used by UNC3569, and notes strong similarities between CROSSWALK and the SideWalk/ScrambleCross backdoor family, suggesting shared development lineage. Crosswalk has also been referenced as part of the broader Winnti/APT41 tooling set and as a more tightly controlled tool used after earlier widespread malware distribution involving PlugX and ShadowPad.
Observed tradecraft includes DLL side-loading for persistence and execution. In UNC3569 intrusions, CROSSWALK was deployed after exploitation of known n-day vulnerabilities in internet-facing products from vendors including Apache, Microsoft, IBM, VMware, and Oracle. Reporting states UNC3569 commonly used OXEEYE and SIDESTEP during post-exploitation and then installed backdoors including DRAFTGRAPH, CROSSWALK, and the custom GRAYRABBIT for remote control. The malware has also been stored alongside SIDESTEP, OXEEYE, DRAFTGRAPH, and GRAYRABBIT in cloud-hosted infrastructure, including OneDrive-abusing operations.
Crosswalk is linked in the content to PRC-nexus activity targeting organizations worldwide, with sectors including government, education, technology, finance, media, telecommunications, airlines, heavy industry, and energy. Separate reporting ties APT41 activity involving Crosswalk to compromises of software, hardware, telecommunications, social media, video game, nonprofit, university, think tank, and government targets, as well as Hong Kong pro-democracy figures. The content also notes overlap between infrastructure used by actors such as UNC3569 and other China-aligned clusters, and that GRAYRABBIT was found on infrastructure associated with PeckBirdy activity where Crosswalk had previously been deployed alongside DRAFTGRAPH.
High-confidence related references in the content include aliases and variants such as CROSSWALK and ScrambleCross being described as a variant of CROSSWALK. The content does not provide a standalone Crosswalk-specific IOC set, but directly associates it with DLL side-loading, APT41/UNC3569 operations, and co-deployment with DRAFTGRAPH, GRAYRABBIT, SIDESTEP, and OXEEYE.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
To maintain persistence, the group has been observed to perform DLL side loading techniques to launch malware such as HK Door, Crosswalk, and others.
A primary backdoor – DRAFTGRAPH, CROSSWALK or the custom GRAYRABBIT – is included in the attack to offer other remote control features.
...the SideWalk backdoor shares multiple similiarities with CROSSWALK, which is a modular backdoor attributed to APT41...
Techniques & procedures
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Resource Development
1 technique
Resource Development
Initial Access
1 technique
Initial Access
Command and Control
2 techniques
Command and Control
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tooling mentioned as being deployed alongside GRAYRABBIT by UNC3569 after exploiting N-day vulnerabilities; no functional details provided in the content.
An advanced malware tool referenced as part of the actor’s more controlled dissemination of tooling.
APT41-associated malware family described by Mandiant; ScrambleCross/SideWalk is characterized here as a variant of CROSSWALK.
Modular backdoor with architectural similarities to SideWalk (threading model, data layout, anti-tampering, proxy handling, module install/uninstall/execute). Reported as attributed to APT41 in prior public reporting.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.