SECURITYTHE HACKER NEWS
Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
An independent malware researcher documented SLEEPWALKER, a previously unreported Windows backdoor. This sample is an unsigned 64-bit DLL that remains inert in memory until it receives a specifically crafted network packet. Once triggered, the backdoor executes commands written in its own unique 23-instruction language.
Mentioned
Related Signal
Adjacent reporting
- New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials
- Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package
- One of many reasons why you don't want to store your keys on a computer or server: Microsoft secretly built a backdoor into BitLocker
- Security researcher says Microsoft built a Bitlocker backdoor, releases exploit