{
  "id": 3276488,
  "title": "New Windows Backdoor Can Hide Silently Until Hackers Activate It",
  "url": "https://urgent.news/2026/08/25/new-windows-backdoor-can-hide-silently-until-hackers-activate-it",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-25T13:36:33.000Z",
  "source": {
    "name": "ProPakistani",
    "slug": "propakistani",
    "url": "https://propakistani.pk/2026/08/25/new-windows-backdoor-can-hide-silently-until-hackers-activate-it/"
  },
  "original_language": "en",
  "account": "Security researchers have uncovered a new, previously undetected Windows backdoor called Sleepwalker. This malicious software can remain dormant on an infected computer until an attacker sends it a secret network signal, making it harder to detect. Unlike typical malware, Sleepwalker does not frequently connect to an attacker's server or maintain an open connection. Instead, it patiently waits for a specially crafted network packet before activating. The malware's activation requires a unique \"magic packet\" – a specially designed network message that functions as a secret password. Once the correct packet is received, Sleepwalker decrypts instructions from the attacker and begins executing them. The malware possesses a set of 23 commands that allow attackers to perform tasks such as transferring data, downloading additional malware, and executing code within the infected computer's memory. Sleepwalker employs AES-256-CCM encryption to secure these instructions, but knowing the encryption key alone is insufficient. Researchers must also comprehend Sleepwalker's custom command system to fully understand the attacker's commands. This backdoor can communicate over various network connections, such as TCP, UDP, ICMP, and SMB named pipes, as well as through VMware's VMCI technology. Researchers also discovered a mechanism that could potentially enable Sleepwalker to use DNS as a trigger, although this feature was not active in the analyzed sample. One significant concern is that Sleepwalker disguises itself as a legitimate Windows component, specifically a DLL file named dpapi.dll, which is also a genuine Microsoft Windows component. This further complicates its detection, as the malicious file shares the same name as a legitimate system file. Sleepwalker utilizes a technique called DLL side-loading, where a malicious file is tricked into being loaded by a legitimate program. It verifies whether it has been loaded by the ESET Management Agent executable (ERAAgent.exe) and only activates if it is running within that program. If not, it remains dormant. Once activated, the malware creates a background process, prepares computer memory for its instructions, and begins monitoring network traffic for its secret activation signal. Most security systems typically look for signs like an infected computer repeatedly connecting to a suspicious external server. However, Sleepwalker avoids this behavior by remaining hidden and waiting for the appropriate network packet, potentially allowing an infected computer to remain compromised without triggering typical warning signs.",
  "summary": "Security researchers have discovered a previously unknown Windows backdoor that can stay hidden inside an infected computer until an attacker … Read More The post New Windows Backdoor Can Hide Silently Until Hackers Activate It appeared first on ProPakistani .",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}