Urgent.News

What's breaking now, across thousands of outlets.

Tech

You don't want this Sleepwalker backdoor on your Windows machine

Its own command language, 23 instructions - signs point to 'well-resourced operation rather than an opportunistic one'

You don't want this Sleepwalker backdoor on your Windows machine

A newly discovered backdoor called Sleepwalker poses a significant threat to Windows machines. Discovered by malware researcher Dominik Reichel, Sleepwalker remains hidden in memory until triggered by a specific network packet, which activates the malware to execute 23 discreet instructions. Unlike traditional backdoors, Sleepwalker does not initiate outbound communication, making it difficult for network monitors to detect.

The backdoor's unique command language consists of 23 instructions, each represented as raw bytes in a specific order. Its malicious activities include data exfiltration, file staging, code execution in memory, and establishing connections to VMware VMCI targets. The malware masquerades as Microsoft's dpapi.dll, exports seven functions, and employs encryption using AES-256-CCM.

Despite the limited information available about its origin, Sleepwalker demonstrates the potential for targeted, well-resourced operations.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

More from Monday 24 August →