SLEEPWALKER: A Passive Backdoor That Wakes Only for Its Own Secret Command Language
Sleepwalker: Passive Backdoor with Its Own Command Language

A newly discovered Windows backdoor, SLEEPWALKER, hides inside a fake ESET Management Agent DLL and waits passively for a single crafted network packet before executing any code. It carries no payload and contacts no C2 server; instead, it sniffs traffic for a magic trigger, then decrypts and runs a program written in a custom 23-instruction bytecode language. The implant supports scheduling, staged file delivery, in-memory execution, and multiple covert transports including DNS and VMware's VMCI channel. Its design makes it nearly invisible on the network, but its implementation has weaknesses, suggesting it may be an early version.
It waits in memory doing nothing at all until one specifically crafted network packet reaches the machine, which is why I am calling it SLEEPWALKER.
- int0x29
> It is a short sequence of raw bytes that only makes sense when read in a specific order.
This kind of useless sentence is what makes reading AI text so miserable
- ang_cire
This is very cool. Definitely seems like either an early or one-time, targeted attack by someone with good know-how and significant resources, even if it itself is not top-tier. Pretty cool find!
- fabioyy
in my script kid days, ( 30 years ago ) I did something similar for linux , using raw sockets and I think with ETH_P_ALL. embedding into a an already existing regular linux process ( recompiling the source code ) the problem was high cpu usage of the process when network usage was intensive. of course it did't survive when the OS updated the program.