SideWalk is a backdoor trojan first publicly documented by Trend Micro in March 2019, attributed to the Winnti Group (also tracked as APT41, TA523) based on code overlaps and infrastructure. It serves as a second-stage payload in targeted intrusion campaigns, primarily used for espionage and data exfiltration.
SideWalk deploys a modular architecture with a core DLL payload that communicates over HTTP or HTTPS to a hardcoded C2 server using encrypted JSON blobs. It uses a custom encryption algorithm (XOR with a rolling key) for C2 traffic. Persistence is achieved via a scheduled task or Windows service named "MicrosoftEdgeUpdateTask" to masquerade as legitimate software. Evasion techniques include process hollowing into svchost.exe, checking for sandbox environments by verifying disk size or running processes, and employing anti-debugging via NtGlobalFlag checks. Propagation is manual via compromised administrative accounts using RDP or SMB, as SideWalk is delivered only after initial foothold is gained.
SideWalk was first observed in the wild in 2018 but formally analyzed in 2019 after targeted attacks against South Korean gaming companies and technology firms. In 2020, Trend Micro linked SideWalk to the supply-chain compromise of a Japanese IT provider where SideWalk was deployed alongside Sogu and HyperBro backdoors. No high-profile victim names have been publicly released. The Winnti Group continues to use SideWalk as part of its arsenal, though no CVEs are directly associated with the malware itself.
Known SHA1 hashes include 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b (sample file). Behavioral indicators include creation of the registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunMicrosoftEdgeUpdateTask. Network IOCs include C2 domains such as api.techupdate[.]com and cdn.microsoft-software[.]net. The User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" is used for HTTP requests. Mutex name GlobalSideWalk_Mutex was observed in some samples.
SideWalk primarily enables persistent remote access for data theft, keylogging, screen capture, and file exfiltration. It has been used to compromise intellectual property from the gaming and technology sectors. Financial losses are indirect, as the Winnti Group sells stolen credentials and proprietary code on underground forums. No ransomware or destructive payloads have been associated with SideWalk.
Defensive measures include blocking the listed C2 domains at network egress, enabling Windows Defender ATP or EDR solutions with behavioral detection rules for process hollowing, and applying the principle of least privilege to reduce lateral movement. No specific patch exists; detection rules are available in the Trend Micro report TROJ_SIDEWALK.ABC.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.