SLEEPWALKER: A Passive Backdoor That Wakes Only for Its Own Secret Command Language

Sleepwalker: Passive Backdoor with Its Own Command Language

SLEEPWALKER: A Passive Backdoor That Wakes Only for Its Own Secret Command Language

A newly discovered Windows backdoor, SLEEPWALKER, hides inside a fake ESET Management Agent DLL and waits passively for a single crafted network packet before executing any code. It carries no payload and contacts no C2 server; instead, it sniffs traffic for a magic trigger, then decrypts and runs a program written in a custom 23-instruction bytecode language. The implant supports scheduling, staged file delivery, in-memory execution, and multiple covert transports including DNS and VMware's VMCI channel. Its design makes it nearly invisible on the network, but its implementation has weaknesses, suggesting it may be an early version.

It waits in memory doing nothing at all until one specifically crafted network packet reaches the machine, which is why I am calling it SLEEPWALKER.

More from this day

2026-08-29