Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
A previously unreported Windows backdoor, dubbed SLEEPWALKER, has been identified by a malware researcher. The backdoor remains dormant until a specific crafted network packet is received, at which point it executes a custom bytecode language to monitor network interfaces and potentially facilitate lateral movement. It impersonates Microsoft's dpapi.dll and relies on side-loading into ESET Management Agent, requiring local administrator privileges to install. The analysis reveals a complex architecture with multiple transport mechanisms and a focus on stealth, making detection challenging. The backdoor is a post-compromise implant, and its initial infection vector remains unknown.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
