Researchers linked the SideWalk backdoor to multiple China-aligned intrusion sets tied to the broader APT41/Winnti ecosystem, with Symantec attributing recent activity to Grayfly and earlier ESET reporting associating the malware with SparklingGoblin. Recent intrusions hit organizations in Taiwan, Vietnam, the United States, and Mexico, with a strong focus on telecommunications as well as IT, media, finance, academia, and government targets. Investigators said attackers gained access by exploiting exposed Microsoft Exchange and MySQL servers, then deployed web shells, established persistence with scheduled tasks, and stole credentials using a custom Mimikatz variant.
Technical analysis showed SideWalk is a modular backdoor closely related to CROSSWALK, reinforcing assessments of shared developers or operational overlap inside the APT41 ecosystem. ESET found the malware could retrieve infrastructure through Google Docs dead-drop resolvers and use Cloudflare Workers for command-and-control, while TeamT5 later documented a related China-nexus backdoor, Calendarwalk, that used Google Calendar events for C2 and was deployed against Taiwanese IT and ERP organizations in 2024 and 2025. Calendarwalk also used a multi-stage chain involving Windows Workflow Foundation XOML, shellcode loaders, and heavy obfuscation, underscoring a broader pattern of Chinese espionage operators adopting stealthy, cloud-backed malware families for long-term post-compromise access.

TTPs, infrastructure, and targeting history in one profile.
12 events from the most recent confirmed update back to the earliest known activity.
At the Virus Bulletin Conference in September 2025, TeamT5 presented research on Calendarwalk, a newly identified backdoor using Google Calendar as command-and-control infrastructure. The researchers attributed the malware to the China-nexus group Amoeba, also known as APT41 or Earth Baku, and said it had been deployed against Taiwanese victims in 2024 and 2025.
In December 2024, TeamT5 identified two fully undetected samples exploiting Windows Workflow Foundation XOML to execute payloads. One payload was an AES variant of Chatloader, while the other was the previously unseen Calendarwalk backdoor.
TeamT5 found Google Calendar events timestamped 2023-05-30 used for victim information and events timestamped 2023-07-30 used to deliver commands in Calendarwalk operations. Decrypted event data showed the attacker attempted to execute the "query user" command and received victim reporting from a Taiwanese IT company host.
ESET reported that SparklingGoblin deployed a Linux variant of the SideWalk backdoor against a Hong Kong university in February 2021, extending an intrusion at the same institution that began in May 2020. ESET also concluded that the malware previously called StageClient, and the previously documented Specter RAT, are Linux variants of SideWalk.
In May 2020, ESET observed a campaign targeting a previously compromised Hong Kong university using the CROSSWALK backdoor and a PlugX variant that used Google Docs as a dead-drop resolver. ESET began tracking the post-2019 activity as a separate actor that it later named SparklingGoblin.
Symantec noted that three Chinese nationals tied to Chengdu 404 were indicted by the United States in 2020 for attacks involving Grayfly tools and tactics. The report said the group nevertheless appears to have remained active.
ESET telemetry indicates SparklingGoblin was very active from mid-2020 through 2021, targeting victims across academia, government, media, and commercial sectors in Asia and elsewhere. Reported targets included organizations in Macao, Hong Kong, Taiwan, Southeast Asia, South Korea, Canada, India, Bahrain, the USA, and Georgia.
ESET previously observed a Winnti Group campaign starting in late October 2019 that targeted several Hong Kong universities. The operation used ShadowPad, Winnti malware, Spyder, and a DarkShell-based backdoor ESET named Doraemon.
Symantec said the China-linked espionage group Grayfly, also known as GREF and Wicked Panda, has been active since at least March 2017. The group historically used tools including the CROSSWALK backdoor and a custom loader called Chattak.
Symantec said Grayfly's more recent activity concentrated on telecommunications organizations while also affecting IT, media, and finance targets. The intrusions involved exploitation of exposed Microsoft Exchange or MySQL servers, web shell deployment, Sidewalk execution, and credential theft using a custom Mimikatz variant.
Symantec attributed the Sidewalk backdoor to Grayfly and linked it to the older CROSSWALK malware family. The company assessed Grayfly as the espionage arm of APT41 and said the malware was used in recent campaigns against organizations in Taiwan, Vietnam, the United States, and Mexico.
ESET researchers documented a previously unknown modular backdoor named SideWalk and attributed it to the APT cluster SparklingGoblin. The report said SideWalk had been used in a campaign targeting a US-based computer retail company and shared significant similarities with the older CROSSWALK backdoor.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 55 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
symantec-enterprise-blogs.security.com
Open sourcevirusbulletin.com
Open sourcewelivesecurity.com
Open sourcewelivesecurity.com
Open sourceblog.netlab.360.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.