THU 01 OCT   10:46:52

SLEEPWALKER WINDOWS BACKDOOR DISCOVERED BY SECURITY RESEARCHER

TUE 25 AUG 2026 CYBERSECURITY

Malware researcher Dominik Reichel has identified a previously unknown Windows backdoor dubbed Sleepwalker that remains dormant in system memory until activated by a specifically crafted network packet. The backdoor, detailed in a technical analysis on Monday, operates using its own custom command language containing 23 instructions. According to Reichel's account, the malware can execute code directly in memory, schedule tasks, move data between systems and deliver files in stages.

The backdoor is concealed within a 64-bit Windows DLL file that impersonates Microsoft's dpapi.dll, part of Windows' data protection application programming interface. It exports the same seven functions as the legitimate Microsoft component but attempts to forward calls to a non-existent file named dpapisvc.dll. The malware loads via side-loading into ERAAgent.exe, the Windows executable for ESET Management Agent, and carries a forged version resource claiming to be from ESET Management Agent. According to Reichel, the malware can also accept commands from a VMware VMCI target rather than a standard network address.

Reichel assessed the backdoor's design as consistent with a "targeted, well-resourced operation rather than an opportunistic one." The custom command language, passive activation mechanism and sophisticated obfuscation techniques distinguish Sleepwalker from commodity malware. Recovering the encryption key used to protect the activation packet is insufficient to understand the malware's operations; reverse engineers must also decipher the internal command language independently. The discovery suggests an adversary with substantial technical expertise and resources behind the operation.

WATCHALONGS
LIVE WATCH PARTIES ON YOUTUBE, X AND TWITCH
WATCH NOW >>
SPORTP110
LATEST SCORES RESULTS AND FIXTURES ALL IN ONE PLACE
TO SPORT >>
← BACK