SLEEPWALKER Backdoor Targets Microsoft Windows

Researchers have uncovered SLEEPWALKER, a previously undocumented Windows backdoor that remains dormant in memory until activated by a specially crafted network packet. The unsigned DLL impersonates Microsoft’s dpapi.dll and persists through side-loading by ESET Management Agent, but the technique does not exploit an ESET vulnerability and requires prior administrative access. Once triggered, the implant executes a custom 23-instruction bytecode language and supports TCP, UDP, ICMP, SMB named pipes, raw packet capture, and VMware VMCI communications. No victim or threat actor has been identified, and confirmed infections should prompt full incident response, system rebuilding, and checks for unexpected DLLs and registry changes.

Reference: thehackernews.com