Crosswalk is a modular Windows backdoor associated with the China-linked APT41 ecosystem, particularly the espionage cluster commonly tracked as Grayfly, and has also been linked to SparklingGoblin and related Winnti-aligned activity. It has been referred to as Backdoor.Motnug and is closely related to later tooling such as SideWalk and ScrambleCross, which share architectural and implementation similarities and appear to represent evolutionary or refactored successors.
Crosswalk provides comprehensive remote access on compromised systems. Reported capabilities include system reconnaissance, receipt and execution of additional attacker-supplied modules or shellcode, and proxying or pivoting connections into otherwise hard-to-reach network segments. Technical reporting has also documented use of the KCP protocol in Crosswalk communications, placing it among a set of PRC-nexus malware families that adopted that transport. The malware has been described as modular and suitable for long-term post-compromise operations.
Observed deployment patterns place Crosswalk in targeted intrusions against telecommunications, government, academia, media, finance, IT, gaming, and other sectors across Asia and beyond. It has been delivered through multiple intrusion chains, including malicious shortcut and archive-based lure campaigns, exploitation of public-facing servers and N-day vulnerabilities, and post-exploitation deployment after web-shell access. Operators have also used DLL side-loading to launch Crosswalk and have paired it with tooling such as Cobalt Strike, PlugX, ShadowPad, Metasploit components, and custom loaders.
Crosswalk is widely assessed as part of a broader APT41 and Winnti-linked toolset. Its use has been a recurring attribution signal in campaigns tied to Grayfly and other related Chinese espionage clusters, and its code and tradecraft overlaps with SideWalk and ScrambleCross indicate shared development lineage within that ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The shortcuts themselves contain links to pages hosted on Zeplin ... that are used to fetch the final-stage malware that, in turn, includes a shellcode loader ("svchast.exe") and a backdoor called Crosswalk ("3t54dE3r.tmp").
It makes use of Motnug and ChaCha20-based loaders, the CROSSWALK and SideWalk backdoors, along with Korplug (aka PlugX) and Cobalt Strike.
A primary backdoor – DRAFTGRAPH, CROSSWALK or the custom GRAYRABBIT – is included in the attack to offer other remote control features.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
A characteristic of the recent campaign was that the group appeared to be particularly interested in attacking exposed Microsoft Exchange or MySQL servers. This suggests that the initial vector may be the exploit of multiple vulnerabilities against public-facing servers.
The malware uses KCP protocol for backdoor communication... This backdoor has 20 commands and connects with C2 servers via KCP over UDP.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An older custom backdoor associated with Grayfly and described as related to Sidewalk.
Tooling mentioned as being deployed alongside GRAYRABBIT by UNC3569 after exploiting N-day vulnerabilities; no functional details provided in the content.
An advanced malware tool referenced as part of the actor’s more controlled dissemination of tooling.
Mentioned only as another malware family using KCP communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.