logo

SLEEPWALKER Backdoor Uses SMB, ICMP, DNS and VMware VMCI for Covert Communications

ID: 305f8307-cf0c-59af-a2be-25b127acd6e0

STIX ID: report--305f8307-cf0c-59af-a2be-25b127acd6e0

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: Varshini

...
...

Researchers discovered a sophisticated Windows backdoor called SLEEPWALKER that remains dormant until it receives specially crafted encrypted triggers and can receive commands via covert channels including raw network packets, DNS labels, ICMP, SMB named pipes, and VMware VMCI. The unsigned 64-bit DLL impersonates dpapi.dll and is designed to be side-loaded by ESET's ERAAgent.exe; once activated it runs encrypted bytecode supporting 23 instructions for task scheduling, data transfer, staged payload assembly, and in-memory shellcode execution. The implant uses promiscuous-mode packet capture and robust validation (framing, CRC-32, AES-256-CCM) to avoid detection, can weaken SMB security for anonymous pipe access, and shows capabilities rather than confirmed use in the wild or linkage to a specific threat actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.