You don't want this Sleepwalker backdoor on your Windows machine
Its own command language, 23 instructions - signs point to 'well-resourced operation rather than an opportunistic one'
A new Windows backdoor known as Sleepwalker recently emerged, designed to remain hidden in the system's memory. Discovered by malware researcher Dominik Reichel, Sleepwalker waits silently for a specific network packet to activate and execute commands using its own 23-instruction language. Unlike typical backdoors, Sleepwalker does not initiate communication but instead checks packets for a unique "magic packet" pattern.
Once activated, it decrypts commands encrypted with AES-256-CCM, which are sequences of raw bytes rather than readable text or documents. These commands allow the backdoor to perform various actions, such as running code in memory, moving data off the computer, and even establishing connections to VMware VMCI targets. The malware masquerades as Microsoft's dpapi.dll, exporting seven functions but forwarding calls to a non-existent file.
It sideloads into ERAAgent.exe, the Windows executable for ESET Management Agent, and remains hidden from traditional anti-virus tools. Although much remains unknown about Sleepwalker, Reichel has provided a toolkit to decode its bytecode and detect the infection, urging targeted individuals to reach out for assistance.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- You don't want this Sleepwalker backdoor on your Windows machine theregister.com