New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

Read full story on The Hacker News
Share
New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
AI disclosure

Summary

An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design. The sample is an unsigned 64-bit Windows dynamic-link library (DLL) of 59,904 bytes, built to be side-loaded into&

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.