SLEEPWALKER backdoor hides in ESET agent and wakes on a crafted packet
A newly documented Windows backdoor named SLEEPWALKER can remain inactive in memory until it receives a specially formed network packet, then execute commands through a private 23-instruction bytecode. The 59,904-byte unsigned DLL impersonates Microsoft’s `dpapi.dll` while side-loading through ESET Management Agent, but no victim, campaign, or threat actor has been confirmed.
Source
👉@sysadminoff
https://4sysops.com/archives/sleepwalker-backdoor-hides-in-eset-agent-and-wakes-on-a-crafted-packet/
Post #19646
57
