New Windows malware lays dormant until a custom command activates it like a sleeper agent
No one knows who built it and to what end.
A recently discovered piece of malware, dubbed SLEEPWALKER, has been found to operate in an unprecedented manner. Unlike most malware, SLEEPWALKER does not come equipped with a pre-defined set of tools and features such as system fingerprinting, network mapping, data exfiltration, keylogging, screenshots, tapping into the camera and microphone. Instead, it remains almost entirely silent until activated by a custom command.
Security researcher Dominik Reichel, who unearthed this unusual piece of malware, named it SLEEPWALKER. It poses no threat to security software as it does not contain any malicious code. Instead, it disguises itself as a legitimate Windows component for ESET’s Management Agent, allowing it to operate within a trusted app and avoiding scrutiny.
SLEEPWALKER operates by listening to network traffic for a specially crafted signal, which wakes it up. Upon receiving this signal, the malware also "learns" what it can do, including scheduling different activities, communicating with other systems, receiving additional programs, and executing code. This unique approach to activation and functionality has made SLEEPWALKER stand out in the world of cyber threats.
The malware was submitted to VirusTotal last year, but no active campaigns have been confirmed, nor have any victims, industries, countries, or organizations been linked to the sample. Reichel also noted that the code of SLEEPWALKER appears to be somewhat unfinished, suggesting it may have been a work in progress at the time of discovery.
Despite its unique design, SLEEPWALKER carries several weaknesses, which could indicate that it was a work in progress. It is unclear how the malware initially entered the reporter's environment, who runs it, and what additional tools may have accompanied it. Reichel also stated that the code may not represent the most recent version of SLEEPWALKER, as there could be newer variants in circulation.
However, given the nature of the malware, Reichel does not believe it was intended for indiscriminate attacks. Instead, it is likely that SLEEPWALKER was designed by nation-states with specific targets in mind.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.