CrossC2 is an unofficial cross-platform extension of Cobalt Strike that enables Beacon-style post-exploitation on UNIX-like systems, particularly Linux and macOS. It is implemented in C, supports multiple processor architectures, and is commonly used as a Linux-compatible or cross-platform Beacon payload in intrusion operations after an initial foothold has been established.
CrossC2 is primarily associated with post-compromise activity rather than initial access. Reported deployments show it being installed after exploitation of internet-facing services or after other loaders and downloaders execute on a compromised host. Observed delivery chains include Bash-based installers on Linux and multi-stage loader chains that culminate in in-memory execution of Cobalt Strike components. In some campaigns, CrossC2 has been installed following exploitation of CVE-2025-55182, while other incidents involved custom loaders and DLL sideloading chains that ultimately launched Cobalt Strike tooling.
The malware is used for remote command execution and broader post-exploitation operations on Linux and macOS systems. It has been observed alongside credential theft utilities, keyloggers, SSH brute-force tools, TinyShell, Sliver, PsExec, Plink, and SystemBC, indicating use in lateral movement, credential harvesting, and attempts to expand access into core enterprise or telecommunications environments. In telecom intrusions, operators used CrossC2 after compromising edge infrastructure to move deeper into sensitive networks.
Technical reporting describes CrossC2 payloads as commonly packed with UPX and storing encrypted configuration data at the end of the executable. The configuration is decrypted with AES-128-CBC, and samples have included anti-analysis measures such as XOR-encoded strings and junk-code insertion. CrossC2 can also obtain command-and-control parameters from environment variables. On execution, it may fork and continue main processing in the child process.
CrossC2 has been observed in campaigns attributed or linked to multiple threat actors, including activity associated with Red Menshen in telecommunications espionage and incidents assessed as potentially connected to Black Basta tradecraft. It has also appeared in broad opportunistic exploitation campaigns targeting vulnerable Linux servers. Its role across these operations is consistent: providing a stealthy, cross-platform Cobalt Strike capability for persistence, command execution, and follow-on intrusion activity on non-Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The a_x86 / a_x64 ELF executables are the CrossC2 framework payloads for Cobalt Strike, designed for UNIX-like systems. | The threat actors leveraged the CVE‑2025‑55182 (React2Shell) vulnerability... React2Shell is a vulnerability in the Flight protocol, which facilitates client-server communication for React Server Components. The vulnerability stems from insecure deserialization... Under certain conditions, this can enable an attacker to execute arbitrary code on the server.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Once inside, attackers deploy tools such as CrossC2 for command execution, TinyShell for stealthy persistence, and keyloggers or brute-force tools to steal credentials and move laterally toward core systems.
Upon gaining a successful foothold, Linux-compatible beacon frameworks such as CrossC2 are deployed to facilitate post-exploitation activities.
Upon gaining a successful foothold, Linux-compatible beacon frameworks such as CrossC2 are deployed to facilitate post-exploitation activities.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Once inside, attackers deploy tools such as CrossC2 for command execution...
Attacks usually begin at the network edge by exploiting exposed services or valid accounts on devices like VPNs, firewalls, and virtualization hosts.
The script also establishes persistence by creating a systemd service /etc/systemd/system/apaches-main.service... If executed with root privileges... creates a systemd service... CrossC2 check.sh creates and starts a service... EtherRAT establishes persistence through: systemd.
Attacks usually begin at the network edge by exploiting exposed services or valid accounts on devices like VPNs, firewalls, and virtualization hosts.
The script also establishes persistence by creating a systemd service /etc/systemd/system/apaches-main.service... If executed with root privileges... creates a systemd service... CrossC2 check.sh creates and starts a service... EtherRAT establishes persistence through: systemd.
Depending on privileges, the script saved the file as rsyslo either in /usr/local/rsyslo ... or in ${HOME}/.rsyslo ... Description=Rsyslo AV Agent Service ... executed from an anonymous file descriptor created with memfd_create, as a [kworker/0:2] process.
The a_x86 / a_x64 files use the same C2 server: 154.89.152[.]240:443 ... MeshServer=wss://156.67.221[.]96:443/agent.ashx ... The malware sends a query to this C2 server ... GET /api/{rand4hex}/{botID}/...
This script downloaded the XMRig cryptocurrency miner... The attackers also loaded the d5.sh Bash script onto the compromised host to download the Sliver implant... The attackers employed the check.sh Bash script to download ELF executables (a_x86 / a_x64) from a server.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Related articles CrossC2 Expanding Cobalt Strike Beacon to Cross-Platform Attacks
A cross-platform command execution framework used post-compromise to execute commands within targeted environments.
A Linux-compatible beacon framework used post-compromise to facilitate post-exploitation activities.
A post-exploitation tool used in the campaign after initial compromise.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.