{
  "id": 3248287,
  "title": "Windows Backdoor 'Sleepwalker' Hides in Memory Until Activated by a 'Magic Packet'",
  "url": "https://urgent.news/2026/08/25/windows-backdoor-sleepwalker-hides-in-memory-until-activated-by-a",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-25T11:00:00.000Z",
  "source": {
    "name": "Slashdot",
    "slug": "slashdot",
    "url": "https://it.slashdot.org/story/26/08/25/062246/windows-backdoor-sleepwalker-hides-in-memory-until-activated-by-a-magic-packet"
  },
  "original_language": "en",
  "account": "A new Windows backdoor, called Sleepwalker, has been discovered by malware researcher Dominik Reichel. This backdoor remains dormant in memory until it receives a specific network packet, known as a \"magic packet,\" which then activates it and allows it to carry out commands using a 23-instruction language. The commands can range from running code directly in memory to moving data off the infected computer.\n\nUnlike other backdoors, Sleepwalker does not initiate outgoing traffic or open any listening ports, making it difficult for traditional anti-virus tools to detect. Instead, it waits silently for the magic packet to arrive, then decrypts the data and treats it as a command.\n\nThe backdoor's command language consists of 23 instructions covering scheduling, data movement, staged file delivery, and running code directly in memory. However, simply recovering the encryption key is not enough to understand one of these programs, as the internal command language must also be reverse engineered.\n\nSleepwalker disguises itself as Microsoft's dpapi.dll, imitating its seven functions and exporting them. It also imports and side-loads a forged ESET Management Agent version resource, loading via the Windows executable for ESET Management Agent (ERAAgent.exe). Once it confirms its host process is named ERAAgent.exe, Sleepwalker goes to sleep in the computer's memory, effectively remaining hidden.\n\nThe specific magic packet used to activate Sleepwalker is not a readable command, but a short program written in the backdoor's own command language. This approach suggests a targeted, well-resourced operation rather than an opportunistic one.",
  "summary": "\"The Register has a story about a Windows backdoor that waits silently in memory for a 'magic packet' before springing into action,\" writes Slashdot reader fred133. \"No outgoing traffic, just waiting...\" From the report: Like a sleeper cell awaiting activation, a never-before-seen Windows backdoor dubbed Sleepwalker waits silently in memory for one specifically crafted network packet to wake it…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}