You don’t want this Sleepwalker backdoor on your Windows machine

← Back to the feed

You don’t want this Sleepwalker backdoor on your Windows machine

The Register · 10 hours ago

Security researcher Dominik Reichel has identified a previously unseen Windows backdoor, dubbed Sleepwalker, that lurks silently in a compromised machine's memory until a specially crafted network packet activates it. Unlike typical malware, it never contacts a command-and-control server or opens a listening port, making it invisible to network monitoring tools that watch for suspicious outbound connections, and its use of a bespoke 23-instruction command language suggests it is the work of a well-resourced, targeted operation rather than opportunistic attackers.

The malware hides inside a 64-bit DLL disguised as Microsoft's dpapi.dll, side-loading itself into ESET Management Agent's executable, ERAAgent.exe, using a forged version resource. It stays dormant, monitoring passing network traffic for a specific "magic packet", which it then decrypts using AES-256-CCM before executing the embedded commands, ranging from scheduling tasks and staged file delivery to running code directly in memory and exfiltrating data, with some commands even able to target VMware VMCI hosts instead of standard network addresses.

  • New Windows backdoor "Sleepwalker" hides silently until triggered remotely
  • No outbound traffic, so it evades typical network security monitoring
  • Uses a custom 23-instruction language and disguises itself as ESET software

Business Markets

Read the full article at the source →