Sleepwalker: Backdoor hides extremely well in Windows systems

A previously unknown Windows backdoor called Sleepwalker can hide discreetly in the RAM of an infected computer and wait there for a specially prepared data package to activate it.
Hardly noticeable
The backdoor was discovered and analyzed by the malware researcher Dominik Reichel. Sleepwalker therefore differs significantly from many classic backdoors. The malware does not contact a command and control server on its own and does not open any conspicuous network ports by default. Instead, it examines traffic according to a specific pattern. If the matching package is found, the malware decrypts its contents and executes the instructions contained therein. What is particularly unusual is the malware’s own command format. Sleepwalker uses a programming language consisting of 23 instructions, the commands of which are transmitted as short byte sequences. Among other things, it allows code to be executed directly in memory, data to be moved, other tasks to be received, and programs to be created and started.
The malware is contained in a 64-bit DLL that masquerades as Microsoft’s dpapi.dll. It imitates the seven exported functions of the legitimate Windows component and attempts to redirect calls to a non-existent file called dpapisvc.dll. Using so-called DLL sideloading, Sleepwalker is then loaded via the ESET Management Agent executable file. After checking whether the process is actually called ERAAgent.exe, the backdoor retreats into memory.
Origin unclear
This approach is particularly effective for camouflage: Because Sleepwalker does not require any outgoing connections, classic monitoring mechanisms can easily miss the malware. However, it is still unclear who is behind the malware and how it gets onto systems. Reichel has so far been unable to link any specific attack, victim or known group to Sleepwalker. There is also no reliable information about possible variants or an ongoing campaign. The researcher has to own information Developed tools to examine Sleepwalker’s bytecode and network data without actually executing the commands. In addition, a containment guide is available.
Research Snipers is currently covering all technology news including Google, Apple, Android, Xiaomi, Huawei, Samsung News, and More. Research Snipers has decade of experience in breaking technology news, covering latest trends in tech news, and recent developments.