You don't want this Sleepwalker backdoor on your Windows machine
Its own command language, 23 instructions - signs point to 'well-resourced operation rather than an opportunistic one'
A newly discovered backdoor called Sleepwalker poses a significant threat to Windows machines. Discovered by malware researcher Dominik Reichel, Sleepwalker remains hidden in memory until triggered by a specific network packet, which activates the malware to execute 23 discreet instructions. Unlike traditional backdoors, Sleepwalker does not initiate outbound communication, making it difficult for network monitors to detect.
The backdoor's unique command language consists of 23 instructions, each represented as raw bytes in a specific order. Its malicious activities include data exfiltration, file staging, code execution in memory, and establishing connections to VMware VMCI targets. The malware masquerades as Microsoft's dpapi.dll, exports seven functions, and employs encryption using AES-256-CCM.
Despite the limited information available about its origin, Sleepwalker demonstrates the potential for targeted, well-resourced operations.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- You don't want this Sleepwalker backdoor on your Windows machine theregister.com