# Researcher documents packet-triggered SLEEPWALKER Windows backdoor

_Wednesday, August 26, 2026 at 3:12 AM EDT · Security, Infrastructure · Latest · Tier 2 — Notable_

![Researcher documents packet-triggered SLEEPWALKER Windows backdoor — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSnbO35IDgg9dQouCuUCpAko8PiGwwI3lhn7I68m0Ok-PGL84lR1CU0sKk5rWfurFY7u1Fz-9U0-CXi1VCuAVpZDpKF3uDnvtyb062Kls6vW8L7xkTnZBPPJteihNrIWV3C__6JMphWMC7ER4_2bsgKDfzIuq5naTBB3pgZvKvD2v4djmpMh96F62y8Qg/s1700-e365/sleepwalker.jpg)

An independent researcher has documented SLEEPWALKER, a previously unreported Windows backdoor that remains inactive until a crafted network packet triggers its custom bytecode commands. The analyzed unsigned DLL is designed to be side-loaded into ESET Management Agent's ERAAgent.exe and can use several transports, including TCP, UDP, ICMP and VMware VMCI. The researcher had only one binary with no collection context and could not identify a victim, country, actor, or evidence that it was deployed.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/newly-sleepwalker-backdoor-waits-for.html)

---
Canonical: https://techandbusiness.org/newswire/z-ivXQi2arHS9vk7UFUbcK
Retrieved: 2026-08-26T10:40:11.304Z
Publisher: Tech & Business (techandbusiness.org)
