TGViewer
Linux Linux @sysadminoff · 2.13K subscribers
Post #19646 57
SLEEPWALKER backdoor hides in ESET agent and wakes on a crafted packet

A newly documented Windows backdoor named SLEEPWALKER can remain inactive in memory until it receives a specially formed network packet, then execute commands through a private 23-instruction bytecode. The 59,904-byte unsigned DLL impersonates Microsoft’s `dpapi.dll` while side-loading through ESET Management Agent, but no victim, campaign, or threat actor has been confirmed.
Source

👉@sysadminoff

https://4sysops.com/archives/sleepwalker-backdoor-hides-in-eset-agent-and-wakes-on-a-crafted-packet/
More from @sysadminoff
  1. Oct 6, 2026📰 AMD Sends In More New GPU Hardware Enablement For Linux 7.4, Bug Fixes We are nearing t…
  2. Oct 6, 2026⚔️ New Bachata S4 PS4 Emulator UPDATE on Mali GPU is FINALLY Working! - New PanVK Drivers?…
  3. Oct 6, 2026Опубликован дистрибутив ROSA Fresh 13.3 Компания НТЦ ИТ РОСА опубликовала дистрибутив ROSA…
  4. Oct 6, 2026Релиз altctl 1.3.0 (alt-linux-toolkit) — инструмента для автоматизации обслуживания систем…
  5. Oct 6, 2026📰 Arm Working On "TLBID" For Linux To Increase Performance On High Core Count CPUs Arm se…
  6. Oct 6, 20267 Advanced Docker Compose Tricks to Clean Up Multi-Container Stacks in Linux The post 7 Ad…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →