CrossC2 is a cross-platform command-and-control framework and unofficial Cobalt Strike Beacon builder used to deploy remote-access implants on Linux and macOS. Developed in C, it supports Linux x86 and x64 systems and macOS x86, x64, and Apple Silicon systems, and is compatible with Cobalt Strike version 4.1 and later. Its builder is publicly available, although the builder and Beacon source code are not released. Attackers use CrossC2 for remote command execution and post-exploitation access on compromised systems.
CrossC2 implants fork on execution and perform their main processing in the child process. They store encrypted configuration data at the end of the executable and decrypt it using AES-128-CBC through OpenSSL functions. Command-and-control destinations can also be supplied through environment variables. Anti-analysis mechanisms include single-byte XOR string encoding and extensive junk-code insertion. Generated Beacons are packed with UPX by default; appended configuration data complicates standard unpacking. Observed Linux deployment scripts establish persistence through systemd services masquerading as security software.
CrossC2 has been used by the China-linked Red Menshen threat group in telecommunications espionage campaigns targeting providers in the Middle East and Asia. It has also appeared in intrusions investigated in Japan during 2024 and in December 2025 attacks exploiting CVE-2025-55182, known as React2Shell. In React2Shell campaigns, attackers deployed Linux CrossC2 implants through Bash downloaders after compromising vulnerable servers. CrossC2 is used alongside other post-exploitation tools and is not exclusive to a single threat actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
2025年12月3日(現地時間)、React Server Components(RSC)における認証不要のリモートコード実行の脆弱性(CVE-2025-55182)が公開されました。JPCERT/CCでは、この攻撃の被害報告を複数受けています。 | 2025-12-06 19:31 SNOWLIGHTのダウンローダー(javas)、CrossC2(rsyslo)の設置
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Once inside, attackers deploy tools such as CrossC2 for command execution, TinyShell for stealthy persistence, and keyloggers or brute-force tools to steal credentials and move laterally toward core systems.
Upon gaining a successful foothold, Linux-compatible beacon frameworks such as CrossC2 are deployed to facilitate post-exploitation activities.
Upon gaining a successful foothold, Linux-compatible beacon frameworks such as CrossC2 are deployed to facilitate post-exploitation activities.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Once inside, attackers deploy tools such as CrossC2 for command execution...
Attacks usually begin at the network edge by exploiting exposed services or valid accounts on devices like VPNs, firewalls, and virtualization hosts.
The script also establishes persistence by creating a systemd service /etc/systemd/system/apaches-main.service... If executed with root privileges... creates a systemd service... CrossC2 check.sh creates and starts a service... EtherRAT establishes persistence through: systemd.
Attacks usually begin at the network edge by exploiting exposed services or valid accounts on devices like VPNs, firewalls, and virtualization hosts.
The script also establishes persistence by creating a systemd service /etc/systemd/system/apaches-main.service... If executed with root privileges... creates a systemd service... CrossC2 check.sh creates and starts a service... EtherRAT establishes persistence through: systemd.
Depending on privileges, the script saved the file as rsyslo either in /usr/local/rsyslo ... or in ${HOME}/.rsyslo ... Description=Rsyslo AV Agent Service ... executed from an anonymous file descriptor created with memfd_create, as a [kworker/0:2] process.
the malware tries to connect to the C&C with an IP address of 45[.]76[.]220[.]46 on port 40443. This provides shell access to the attackers.
This script downloaded the XMRig cryptocurrency miner... The attackers also loaded the d5.sh Bash script onto the compromised host to download the Sliver implant... The attackers employed the check.sh Bash script to download ELF executables (a_x86 / a_x64) from a server.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related articles as a tool extending Cobalt Strike Beacon cross-platform; not part of the main event.
Related articles CrossC2 Expanding Cobalt Strike Beacon to Cross-Platform Attacks
A cross-platform command execution framework used post-compromise to execute commands within targeted environments.
A Linux-compatible beacon framework used post-compromise to facilitate post-exploitation activities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.