Security researcher Dominik Reichel uncovered a sophisticated Windows backdoor called Sleepwalker that resides stealthily in memory, waiting for a specific encrypted network packet to activate its unique 23-instruction command language. Disguised as Microsoft’s dpapi.dll and loaded via side-loading into an ESET Management Agent process, Sleepwalker avoids detection by not initiating outbound traffic or listening on network ports, indicating a well-resourced targeted operation rather than opportunistic malware. While many details about its deployment and operators remain unknown, Reichel has released tools and guidance to detect and mitigate the threat.
You Don’t Want This Sleepwalker Backdoor on Your Windows Machine

