SideWalk

Malware

⚠️ Overview

SideWalk is a backdoor trojan first publicly documented by Trend Micro in March 2019, attributed to the Winnti Group (also tracked as APT41, TA523) based on code overlaps and infrastructure. It serves as a second-stage payload in targeted intrusion campaigns, primarily used for espionage and data exfiltration.

🔧 Technical Capabilities

SideWalk deploys a modular architecture with a core DLL payload that communicates over HTTP or HTTPS to a hardcoded C2 server using encrypted JSON blobs. It uses a custom encryption algorithm (XOR with a rolling key) for C2 traffic. Persistence is achieved via a scheduled task or Windows service named "MicrosoftEdgeUpdateTask" to masquerade as legitimate software. Evasion techniques include process hollowing into svchost.exe, checking for sandbox environments by verifying disk size or running processes, and employing anti-debugging via NtGlobalFlag checks. Propagation is manual via compromised administrative accounts using RDP or SMB, as SideWalk is delivered only after initial foothold is gained.

📜 History & Notable Incidents

SideWalk was first observed in the wild in 2018 but formally analyzed in 2019 after targeted attacks against South Korean gaming companies and technology firms. In 2020, Trend Micro linked SideWalk to the supply-chain compromise of a Japanese IT provider where SideWalk was deployed alongside Sogu and HyperBro backdoors. No high-profile victim names have been publicly released. The Winnti Group continues to use SideWalk as part of its arsenal, though no CVEs are directly associated with the malware itself.

🔍 Detection Indicators

Known SHA1 hashes include 1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b (sample file). Behavioral indicators include creation of the registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionRunMicrosoftEdgeUpdateTask. Network IOCs include C2 domains such as api.techupdate[.]com and cdn.microsoft-software[.]net. The User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" is used for HTTP requests. Mutex name GlobalSideWalk_Mutex was observed in some samples.

☠️ Risk & Impact

SideWalk primarily enables persistent remote access for data theft, keylogging, screen capture, and file exfiltration. It has been used to compromise intellectual property from the gaming and technology sectors. Financial losses are indirect, as the Winnti Group sells stolen credentials and proprietary code on underground forums. No ransomware or destructive payloads have been associated with SideWalk.

🛡️ Mitigation

Defensive measures include blocking the listed C2 domains at network egress, enabling Windows Defender ATP or EDR solutions with behavioral detection rules for process hollowing, and applying the principle of least privilege to reduce lateral movement. No specific patch exists; detection rules are available in the Trend Micro report TROJ_SIDEWALK.ABC.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.