news.mlab.sh
Back to the feed
threat-intel

Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

High
Image: The Hacker News
Summary

A previously unreported Windows backdoor, dubbed SLEEPWALKER, has been identified by a malware researcher. The backdoor remains dormant until a specific crafted network packet is received, at which point it executes a custom bytecode language to monitor network interfaces and potentially facilitate lateral movement. It impersonates Microsoft's dpapi.dll and relies on side-loading into ESET Management Agent, requiring local administrator privileges to install. The analysis reveals a complex architecture with multiple transport mechanisms and a focus on stealth, making detection challenging. The backdoor is a post-compromise implant, and its initial infection vector remains unknown.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.