SideWalk is a modular, multipurpose backdoor used in cyber-espionage operations associated with China-linked threat activity. It is principally attributed to SparklingGoblin, a cluster linked to the wider Winnti ecosystem, and has also been linked to Grayfly, which has been characterized as an APT41 espionage element. SideWalk is also known as ScrambleCross; the Linux implementation was previously tracked as StageClient, and Specter RAT has been assessed as another SideWalk Linux variant.
SideWalk supports encrypted HTTP/HTTPS command-and-control, proxy-aware communications, victim fingerprinting, remote command execution, and modular functionality. Windows variants use a dead-drop resolver and cloud-hosted command-and-control infrastructure, while Linux variants include modules for system-information collection and scheduled execution of received shell commands. SideWalk and its Linux variants use ChaCha20-based encryption and compressed, asynchronous network messaging. Windows deployment chains have used obfuscated .NET loaders, InstallUtil execution, scheduled-task persistence, encrypted shellcode, and process hollowing into legitimate processes. Linux-focused campaigns have used the Fast Reverse Proxy tool to establish encrypted tunnels that support remote access, payload deployment, and data transfer.
SideWalk has targeted organizations in academia, government, telecommunications, IT, media, finance, and commercial sectors across East and Southeast Asia as well as globally. Observed victims include a Hong Kong university and organizations in Taiwan, Vietnam, the United States, and Mexico. Delivery has included exploitation of exposed public-facing servers, including attacks exploiting CVE-2024-36401 in GeoServer to deploy multi-architecture Linux payloads. In other intrusions, operators associated with SideWalk activity compromised internet-facing enterprise servers, installed web shells, and used credential-dumping tools after backdoor deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Last year, a critical GeoServer flaw (CVE-2024-36401, CVSS score: 9.8) was exploited into botnets, cryptocurrency miners, and the SideWalk backdoor. | “Last year, a critical GeoServer flaw (CVE-2024-36401, CVSS score: 9.8) was exploited into botnets, cryptocurrency miners, and the SideWalk backdoor.”
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ESET researchers have discovered a Linux variant of the SideWalk backdoor... We originally named this backdoor StageClient, but now refer to it simply as SideWalk Linux.
Symantec, part of Broadcom Software, has linked the recently discovered Sidewalk backdoor to the China-linked Grayfly espionage group.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
A characteristic of the recent campaign was that the group appeared to be particularly interested in attacking exposed Microsoft Exchange or MySQL servers. This suggests that the initial vector may be the exploit of multiple vulnerabilities against public-facing servers.
MITRE ATT&CK techniques ... Command and Control T1071.001 Application Layer Protocol: Web Protocols SideWalk Linux communicates via HTTPS with the C&C server.
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor mentioned only as a historical payload associated with exploitation of a separate GeoServer vulnerability; the content provides no further behavior details.
A recently discovered backdoor used in Grayfly espionage campaigns, providing remote access within compromised networks and used after initial intrusion via exposed public-facing servers and web shells.
SideWalk is a modular backdoor used by various threat actors for persistent access and command execution on compromised systems. It was distributed via exploitation of the GeoServer vulnerability.
SideWalk (ScrambleCross) is a backdoor malware used by Chinese APTs for persistent access and command and control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.