Urgent.News

What's breaking now, across thousands of outlets.

Tech

New Windows Backdoor Can Hide Silently Until Hackers Activate It

Security researchers have discovered a previously unknown Windows backdoor that can stay hidden inside an infected computer until an attacker … Read More The post New Windows Backdoor Can Hide Silently Until Hackers Activate It appeared first on ProPakistani .

New Windows Backdoor Can Hide Silently Until Hackers Activate It

Security researchers have uncovered a new, previously undetected Windows backdoor called Sleepwalker. This malicious software can remain dormant on an infected computer until an attacker sends it a secret network signal, making it harder to detect. Unlike typical malware, Sleepwalker does not frequently connect to an attacker's server or maintain an open connection.

Instead, it patiently waits for a specially crafted network packet before activating. The malware's activation requires a unique "magic packet" – a specially designed network message that functions as a secret password. Once the correct packet is received, Sleepwalker decrypts instructions from the attacker and begins executing them.

The malware possesses a set of 23 commands that allow attackers to perform tasks such as transferring data, downloading additional malware, and executing code within the infected computer's memory. Sleepwalker employs AES-256-CCM encryption to secure these instructions, but knowing the encryption key alone is insufficient. Researchers must also comprehend Sleepwalker's custom command system to fully understand the attacker's commands.

This backdoor can communicate over various network connections, such as TCP, UDP, ICMP, and SMB named pipes, as well as through VMware's VMCI technology. Researchers also discovered a mechanism that could potentially enable Sleepwalker to use DNS as a trigger, although this feature was not active in the analyzed sample. One significant concern is that Sleepwalker disguises itself as a legitimate Windows component, specifically a DLL file named dpapi.dll, which is also a genuine Microsoft Windows component.

This further complicates its detection, as the malicious file shares the same name as a legitimate system file. Sleepwalker utilizes a technique called DLL side-loading, where a malicious file is tricked into being loaded by a legitimate program. It verifies whether it has been loaded by the ESET Management Agent executable (ERAAgent.exe) and only activates if it is running within that program.

If not, it remains dormant. Once activated, the malware creates a background process, prepares computer memory for its instructions, and begins monitoring network traffic for its secret activation signal. Most security systems typically look for signs like an infected computer repeatedly connecting to a suspicious external server.

However, Sleepwalker avoids this behavior by remaining hidden and waiting for the appropriate network packet, potentially allowing an infected computer to remain compromised without triggering typical warning signs.

Written by urgent.news from ProPakistani's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at propakistani.pk →

More in Tech

State-backed hackers targeted EU officials on WhatsApp, document shows

Cyber spies use custom lures to hack "high-ranking officials," EU's internal cyber unit warns.

  • Foreign governments, including Russia, targeted EU officials on WhatsApp.
  • State-sponsored spearphishing used personalized messages to infiltrate accounts.
  • EU cybersecurity officials identified eight significant incidents this year.

More from Tuesday 25 August →