Windows

Sleepwalker: Backdoor hides extremely well in Windows systems

A previously unknown Windows backdoor called Sleepwalker can hide discreetly in the RAM of an infected computer and wait there for a specially prepared data package to activate it.

Hardly noticeable

The backdoor was discovered and analyzed by the malware researcher Dominik Reichel. Sleepwalker therefore differs significantly from many classic backdoors. The malware does not contact a command and control server on its own and does not open any conspicuous network ports by default. Instead, it examines traffic according to a specific pattern. If the matching package is found, the malware decrypts its contents and executes the instructions contained therein. What is particularly unusual is the malware’s own command format. Sleepwalker uses a programming language consisting of 23 instructions, the commands of which are transmitted as short byte sequences. Among other things, it allows code to be executed directly in memory, data to be moved, other tasks to be received, and programs to be created and started.

The malware is contained in a 64-bit DLL that masquerades as Microsoft’s dpapi.dll. It imitates the seven exported functions of the legitimate Windows component and attempts to redirect calls to a non-existent file called dpapisvc.dll. Using so-called DLL sideloading, Sleepwalker is then loaded via the ESET Management Agent executable file. After checking whether the process is actually called ERAAgent.exe, the backdoor retreats into memory.

Origin unclear

This approach is particularly effective for camouflage: Because Sleepwalker does not require any outgoing connections, classic monitoring mechanisms can easily miss the malware. However, it is still unclear who is behind the malware and how it gets onto systems. Reichel has so far been unable to link any specific attack, victim or known group to Sleepwalker. There is also no reliable information about possible variants or an ongoing campaign. The researcher has to own information Developed tools to examine Sleepwalker’s bytecode and network data without actually executing the commands. In addition, a containment guide is available.

Recent Posts

Apple: iPhone keynote date set! The motto is “Surprise and Shine”

Expensive folding cell phones, cameras in headphones and a change in boss: Apple is introducing…

28 minutes ago

Meta pays $18 billion, rebuilds Instagram, locks out teenagers at night

Meta ends a process about addiction design at Facebook with a billion-dollar payment and conditions:…

31 minutes ago

Bill Gates warns of AI danger: Tech industry trivializes the risks

Mass unemployment, cyberattacks and bioterrorism: Bill Gates paints a bleak picture of artificial intelligence in…

33 minutes ago

Beware of ToxicPanda: This Android Trojan blocks Google Play

A new version of the Android Trojan ToxicPanda threatens users of financial and crypto applications…

36 minutes ago

YouTube: New Liquid Glass look & Live Activities planned for iOS apps

Google is apparently planning a design update for YouTube and YouTube Music on iOS. Discovered…

38 minutes ago

Cyberpunk 2077 meets C64: retro computer Commodore 77 presented

The hardware manufacturer Commodore and the studio CD Projekt Red are bringing a special C64…

42 minutes ago