ScrambleCross, also known as SideWalk, is a modular in-memory Windows backdoor associated with APT41, including activity tracked as Earth Baku. It has been described as a shellcode-based, position-independent implant used in cyberespionage operations against enterprises and government entities, particularly in the Indo-Pacific region, with victims reported across sectors including airlines, automotive, infrastructure, media, publishing, IT, and computer hardware.
ScrambleCross is typically delivered as a payload by the StealthVector and StealthMutant loaders, and has also been observed alongside Cobalt Strike in the same intrusion sets. The malware communicates with command-and-control infrastructure to receive tasking and stage additional plugins in memory, reflecting a modular architecture intended for flexible post-compromise operations. Reported functionality includes encrypted command-and-control communications, support for multiple transport protocols including TCP, HTTP, and HTTPS, and plugin-based expansion of capabilities. It has been assessed as a refactored successor to the earlier Crosswalk backdoor, and later reporting characterizes SneakCross as its successor.
Observed intrusion chains associated with ScrambleCross include exploitation of public-facing Microsoft SQL Server instances, exploitation of Microsoft Exchange ProxyLogon vulnerability CVE-2021-26855 with web-shell deployment, and possible malicious email attachment delivery. In compromised environments, the malware has been used as part of broader espionage activity involving reconnaissance, lateral movement, persistence tooling, privilege escalation, and data theft. ScrambleCross infections have also been identified in investigations involving deeper compromise by APT41-linked operators, including environments where firmware-level persistence was present, although ScrambleCross itself is a user-mode implant rather than a firmware component.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A shellcode-based backdoor, ScrambleCross is one of the two kinds of payloads found in StealthMutant and StealthVector samples, the other being the Cobalt Strike beacon.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We believe it to be the successor to their previous modular backdoor, ScrambleCross, which was mentioned in our previous report.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The Cobalt Strike beacon uses HTTPS to communicate with the C&C server. ScrambleCross uses HTTP/HTTPS to communicate with the C&C server.
some variants of this backdoor abuse Cloudflare Workers... to obscure their C&C server activity
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A shellcode-based backdoor that communicates with a C2 server, handles backdoor commands, and can receive and manipulate plug-ins, though its full plug-in capabilities were not confirmed.
A previous modular backdoor referenced as the predecessor to SneakCross.
In-memory modular implant associated with APT41; observed as supporting evidence in an investigation of a UEFI firmware-level compromise and related infrastructure.
Position-independent, memory-resident backdoor/implant that beacons to C2 to exchange information and load additional plugins in memory; in this campaign it is loaded via StealthVector (C++ DLL loader using a modified ChaCha20 to decrypt an encrypted blob) or StealthMutant (.NET loader using AES-256 and process injection into msdt.exe).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.