New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design.

The sample is an unsigned 64-bit Windows dynamic-link library (DLL) of 59,904 bytes, built to be side-loaded into ERAAgent.exe, the Windows executable for ESET Management Agent.

It impersonates Microsoft’s dpapi.dll, exporting the same seven data protection functions as the genuine system library, and carries a version resource copied from ESET Management Agent.

Read more: thehackernews.com