You don't want this Sleepwalker backdoor on your Windows machine
ID: 352f6f6f-2670-5288-bff9-2983e1c1627d
STIX ID: report--352f6f6f-2670-5288-bff9-2983e1c1627d
Feed Name: The Register (Security)
Sleepwalker is a sophisticated, memory-resident Windows backdoor discovered embedded in a forged dpapi.dll that side-loads into ESET's ERAAgent.exe and remains dormant until it detects a specially crafted network "magic" packet; the packet carries an AES-256-CCM-encrypted short program in the malware's own 23-instruction bytecode language which can schedule tasks, run code in memory, transfer data (including via VMware VMCI and named pipes), and spawn additional programs. The sample shows high stealth and technical complexity but the author observed only one sample with no confirmed victims, campaign linkage, or attribution, and provided tooling and mitigations to decode and detect it.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
