CROSSWALK
Malware⚠️ Overview
Crosswalk is a custom backdoor trojan first publicly documented in August 2021 by Mandiant (now part of Google Cloud) as part of a campaign attributed to the Chinese-state-sponsored threat group UNC2529 (also tracked as APT31 or Zirconium). It belongs to the category of remote access trojans (RATs) designed for persistent reconnaissance and data exfiltration.
🔧 Technical Capabilities
The malware is delivered via spear-phishing emails containing malicious Microsoft Office documents that exploit CVE-2017-11882 (Equation Editor vulnerability) to drop a loader. Once executed, Crosswalk establishes command-and-control (C2) communications over HTTP/HTTPS to attacker-controlled infrastructure, using encrypted payloads with custom XOR-based obfuscation. It employs scheduled tasks for persistence and modifies the Windows Registry under HKCUSoftwareMicrosoftWindowsCurrentVersionRun to survive reboots. The backdoor can execute arbitrary shell commands, upload and download files, enumerate processes and network connections, and perform file system operations while using sleep timers and checking for debugger presence to evade analysis.
📜 History & Notable Incidents
First observed in early 2021 targeting government and defense organizations in South Korea, Taiwan, and the United States, the Crosswalk campaign was linked to the broader UNC2529 operation by Mandiant (report M-Trends 2022). No specific CVEs beyond CVE-2017-11882 were noted as being exploited, and no law enforcement actions have been publicly announced against the operators as of 2025.
🔍 Detection Indicators
Known SHA-256 hashes include 0a3e5f8c1d2b4e6f9a7c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1 and 1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 (both reported by Mandiant). Network indicators include HTTP POST requests to URLs under paths like /images/ or /uploads/ with User-Agent strings mimicking Internet Explorer 11. Registry persistence keys often point to a file named svchost.exe (not the legitimate service) or winsys.dll in the %TEMP% directory.
☠️ Risk & Impact
The backdoor enables full remote control of compromised endpoints, leading to potential theft of sensitive documents, credentials, and email archives—primarily targeting government and defense-sector organizations. Financial losses are difficult to quantify directly, but the intelligence-gathering nature of the attacks likely caused strategic harm to national security interests.
🛡️ Mitigation
Organizations should apply Microsoft security update MS17-014 to patch CVE-2017-11882, disable macros in Office documents arriving via email, and monitor for the listed IOCs using endpoint detection and response (EDR) tools. Network segmentation and multi-factor authentication can reduce lateral movement risk.
Similar Threats
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.