Skip to content
-
Subscribe to our newsletter & never miss our best posts. Subscribe Now!
  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
nextbyte.live
nextbyte.live
  • Home
  • Home
Subscribe
Close

Search

New SLEEPWALKER Backdoor Uses Custom Bytecode to Evade Detection
cybersecurity

New SLEEPWALKER Backdoor Uses Custom Bytecode to Evade Detection

By abde el aziz
August 26, 2026 2 Min Read
0

A previously unreported Windows backdoor called SLEEPWALKER has been documented by an independent malware researcher. The SLEEPWALKER backdoor remains dormant in memory until a specifically crafted network packet triggers it, at which point it executes commands written in a custom 23-instruction bytecode language. This approach makes the malware difficult to detect using conventional network monitoring tools, as it contains no hardcoded domains, IP addresses, or URLs, and makes no outbound connections on its own.

Technical Design and Evasion Methods

The SLEEPWALKER backdoor is a 59,904-byte unsigned 64-bit Windows dynamic-link library (DLL) designed to be side-loaded into ERAAgent.exe, the Windows executable for ESET Management Agent. It impersonates Microsoft’s dpapi.dll by exporting the same seven data protection functions as the genuine system library, complete with a version resource copied from ESET Management Agent. This disguise helps it blend in with legitimate system files.

Commands arrive as bytecode rather than readable text, making the SLEEPWALKER backdoor particularly evasive. The encryption key decrypts into opcodes in a format that exists nowhere but inside this single file. According to Dominik Reichel, a former Palo Alto Networks Unit 42 malware researcher, this approach is “consistent with a targeted, well-resourced operation rather than an opportunistic one.” The embedded configuration uses AES-256-CCM encryption and decrypts into a single instruction that tells the backdoor to monitor every network interface indefinitely for the trigger packet.

Capabilities and Post-Compromise Nature

The 23 instructions in the SLEEPWALKER backdoor’s custom language cover scheduling, data movement, staged file delivery verified against SHA-256 hashes, and direct code execution in memory. These commands operate across six transports: TCP, UDP, ICMP, SMB named pipes with credentialed lateral movement, raw promiscuous capture, and VMware’s Virtual Machine Communication Interface (VMCI). Notably, no instruction writes to disk, meaning any files the backdoor needs must be placed there by another component.

The backdoor functions as a post-compromise implant rather than an entry point, requiring local administrator rights to deploy. Side-loading serves as its only persistence mechanism, reloading each time the ESET Management Agent service starts. Since side-loading exploits Windows DLL search order rather than a software vulnerability, there is no patch available—the response to a confirmed infection is incident response and system rebuild. Detection coverage for the file was reportedly low at the time of analysis, though the researcher provided a YARA rule and PowerShell scanner for hunting across networks.

المصدر: The Hacker News

Author

abde el aziz

Follow Me
Other Articles
SEC’s Proposed Crypto Rules Unlikely to Trigger New ICO Boom
Previous

SEC’s Proposed Crypto Rules Unlikely to Trigger New ICO Boom

New Phishing Platform Uses AI Voice Agents to Unlock Stolen iPhones
Next

New Phishing Platform Uses AI Voice Agents to Unlock Stolen iPhones

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Motorola Previews Android 15 Update and New Themed Icons
  • Critical Avada WordPress Theme Flaw Allows Zero-Click Remote Code Execution
  • The Era of Cheap Smartphones Is Over as Price Hikes Become Permanent
  • Nvidia Details Groq 3 LPX Architecture and First Third-Party Benchmarks
  • OpenAI Model Escaped Restricted Environment to Hack Hugging Face

Recent Comments

  1. Motorola Previews Android 15 Update and New Themed Icons on Samsung rolls out One UI 9 beta 6 for Galaxy S26 series
  2. Critical Avada WordPress Theme Flaw Allows Zero-Click Remote Code Execution on Meta to Pay $18 Billion to Settle Lawsuit Over Teen Safety Concerns
  3. The Era of Cheap Smartphones Is Over as Price Hikes Become Permanent on Google Pixel 11 Pro Fold Review: A Solid Effort Facing Tough Competition
  4. Nvidia Details Groq 3 LPX Architecture and First Third-Party Benchmarks on NVIDIA Launches DLSS 4.5 Ray Reconstruction for RTX Remix and New Titles
  5. OpenAI Model Escaped Restricted Environment to Hack Hugging Face on How to Automate Dependabot Pull Requests Using GitHub Copilot

Archives

  • August 2026

Categories

  • ai
  • crypto
  • cybersecurity
  • gadgets
  • hardware
  • tech
  • web
Copyright 2026 — nextbyte.live. All rights reserved. Blogsy WordPress Theme