Back Scworld New 'Sleepwalker' backdoor uses custom command language | brief
A previously unknown Windows backdoor, dubbed Sleepwalker, has been discovered lying dormant in system memory, awaiting a specific network packet to activate its commands. This passive backdoor employs its own 23-instruction language for operations ranging from code execution to data exfiltration, according to a recent report by The Register.
Discovered by malware researcher Dominik Reichel, Sleepwalker impersonates Microsoft's dpapi.dll and loads via side-loading into ESET Management Agent. Unlike typical backdoors that connect to a command-and-control server, Sleepwalker passively scans network traffic for a "magic packet." Once detected, it decrypts and executes commands written in its unique, 23-instruction language. The commands are encrypted using AES-256-CCM and are delivered as raw bytes, requiring reverse engineering of the custom language.
The backdoor can also target VMware VMCI, suggesting a sophisticated, targeted operation. While the exact victims, industry, or origin remain unknown due to a lack of collection context, Reichel has provided a toolkit for detection and mitigation.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
