Researchers documented a previously unseen Windows backdoor called Sleepwalker that can sit silently on an infected machine until it receives a specially crafted network packet. The malware is a 64-bit DLL masquerading as Microsoft's dpapi.dll, side-loads via ESET Management Agent's ERAAgent.exe, forwards to a fake dpapisvc.dll, and uses an AES-256-CCM-encrypted 23-instruction custom command language to run code in memory, move data, and deliver staged payloads; it can also use VMware VMCI instead of normal network addressing.
Why it matters: This matters because infected systems may show no obvious outbound command-and-control traffic, making the backdoor harder to spot with conventional monitoring. Defenders using ESET Management Agent on Windows should hunt for suspicious dpapi.dll side-loading, fake dpapisvc.dll files, anomalous ERAAgent.exe behavior, and memory-resident malware activity.
2026.08.24
100% relevant
This article establishes the story by introducing the Sleepwalker backdoor's functionality, delivery method, and stealth characteristics as a distinct newly reported malware threat.
← Back to all stories