Skip to main content
Back to Newswire
Security Infrastructure

Researcher documents packet-triggered SLEEPWALKER Windows backdoor

Researcher documents packet-triggered SLEEPWALKER Windows backdoor Image: Primary
An independent researcher has documented SLEEPWALKER, a previously unreported Windows backdoor that remains inactive until a crafted network packet triggers its custom bytecode commands. The analyzed unsigned DLL is designed to be side-loaded into ESET Management Agent's ERAAgent.exe and can use several transports, including TCP, UDP, ICMP and VMware VMCI. The researcher had only one binary with no collection context and could not identify a victim, country, actor, or evidence that it was deployed.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire