SLEEPWALKER Backdoor Hides Inside ESET Agent and Awakens Only on Network Trigger
Brief
SLEEPWALKER is a newly identified passive Windows backdoor designed to remain dormant until it receives a specially crafted network packet.
Unlike conventional backdoors that regularly contact command-and-control (C2) servers, SLEEPWALKER does not contain fixed C2 domains, IP addresses, URLs, or second-stage payloads.
The malware is designed for DLL side-loading through the ESET Management Agent process, ERAAgent. exe . The analyzed sample is an unsigned 64-bit DLL that masquerades as Microsoft’s dpapi. dll .
It carries version information copied from the legitimate ESET Management Agent , helping it blend into a trusted software environment.
Researcher Dominik Reichel discovered SLEEPWALKER and assessed that its design is more consistent with a targeted and well-resourced operation than opportunistic malware.
