< Back to all clusters
[TECHNOLOGY] · 3 sources

started · updated

Sleepwalker backdoor discovered in Windows systems

Researchers have discovered a sophisticated Windows backdoor known as ‘Sleepwalker’ that is designed to remain undetected by traditional security measures. Unlike typical malware that establishes outbound connections to a command server, Sleepwalker remains dormant in a computer's memory, waiting for a specifically crafted ‘magic packet’ to trigger its activation.

Discovered by researcher Dominik Reichel, the malware operates passively by listening to network traffic for the designated packet. Once received, it uses a proprietary 23-instruction command language, encrypted with AES-256-CCM, to execute tasks such as transferring files, running code directly from memory, and scheduling activities. The backdoor can even utilize VMware VMCI for communications in virtualized environments.

Technically, Sleepwalker hides within a 64-bit Windows DLL file by impersonating Microsoft’s ‘dpapi.dll’. It employs side-loading via ‘ERAAgent.exe’, the executable for the ESET Management Agent, to maintain its presence. Due to its targeted nature and advanced evasion techniques, experts suggest the operation is likely the work of a well-resourced actor rather than an opportunistic attacker.

Entities

Dominik Reichel · ESET · Microsoft · VMware

Sources

Sleepwalker – valent [www.valent-blog.eu]
17 days ago