Hispasec•August 26, 2026•🇪🇸Translated from Spanish

SLEEPWALKER Backdoor Activates on Windows via Single Custom Encrypted Packet

SLEEPWALKER is a backdoor for Windows designed to remain inactive until it receives a single custom encrypted network packet. When the packet arrives, the implant decrypts and executes its own bytecode, reducing network footprint and complicating detection.

The backdoor follows an unusual approach on Windows: it does not call home, does not maintain a persistent channel, and avoids the typical beaconing that often reveals malware families. It stays silent, resident in memory, and only activates when it receives one specially crafted network packet. That trigger is enough to start the implant and execute actions without any prior communication from the infected system.

The core of the design lies in how it interprets commands. Instead of text commands or easily inspectable structures, the packet carries a small program in bytecode belonging to a proprietary language with 23 instructions. This mini language allows chaining tasks, moving data, receiving additional stages, and executing code in memory. The goal is to minimize network indicators until the last moment and move logic into a format less obvious to traditional inspection tools.

The camouflage also focuses on discretion. The analyzed sample presents itself as a 64-bit DLL that impersonates dpapi.dll and exports the same seven functions expected from the name, while also falsifying version metadata to appear legitimate, including an appearance linked to ESET. The implant seeks to load via DLL side-loading inside ERAAgent.exe, the executable of the ESET Management Agent used in ESET PROTECT and ESET PROTECT On-Prem deployments. To strengthen control, it only wakes if the host process matches the expected one.

Internal configuration is protected with AES-256-CCM and, in the described case, reduces to a bootstrap instruction that orders indefinite monitoring of network interfaces. From there it can inspect traffic in promiscuous mode and evaluate packets at raw content level, allowing the trigger to be hidden inside IP traffic that might appear routine. An alternative channel for transporting triggers via DNS queries exists but was not activated in the sample.

The backdoor supports several transports for communication and task delivery, including TCP, UDP, ICMP, SMB named pipes, and a VMware VMCI channel between guest and host. A delicate detail: to facilitate unauthenticated access to named pipes, the malware can modify Windows registry values such as EveryoneIncludesAnonymous and NullSessionPipes, lowering the host's security posture. These changes require local administrator privileges, and the analyzed code does not itself confirm a privilege-escalation path.

No confirmed victims, sectors, countries, or attributed infrastructure have been identified, and the public analysis is based on a single sample without associated incident telemetry. Nevertheless, the approach fits targeted operations: it reduces network footprint, avoids dependence on a fixed C2, and can wait for the right moment to activate.

Immediate defensive measures include auditing endpoints with ESET Management Agent and checking for an unexpected dpapi.dll in the same directory as ERAAgent.exe. Analysts should also look for dpapisvc.dll next to the executable, a name that does not correspond to a standard Windows component. Researchers have published YARA rules and read-only scanning utilities to confirm matches by hash and characteristic artifacts. If activity is suspected, review and correct the values of EveryoneIncludesAnonymous and NullSessionPipes against a baseline. Hardening DLL loading and trimming the side-loading surface with directory integrity controls and policies that limit loads from unexpected paths are also recommended.

Related articles

BoletimSec•Malware & Botnets

Attackers Abuse Legitimate Microsoft Defender Exclusions to Conceal Malware

Huntress researchers have detailed an evasion technique in which threat actors avoid disabling Microsoft Defender entirely. Instead, they create targeted exclusions for specific folders or file extensions, allowing malware to operate undetected while the protection status remains apparently active. These exclusions are configured through PowerShell commands, Windows Management Instrumentation, Group Policy, or direct registry modifications, all requiring administrator privileges after initial compromise. A registry key named HideExclusionsFromLocalAdmins can further conceal the list of exclusions from local administrators viewing the interface. The approach has been linked to campaigns involving GootKit in 2019, WhisperGate in 2022 that excluded the entire C: drive, and Muddled Libra in 2024. Defenders are advised to monitor registry changes directly, as this bypasses interface hiding, and to flag exclusions of entire drives or common directories such as temporary and downloads folders.

AntiMalware•Malware & Botnets

SC Malware on WordPress Restores Deleted Backdoors in Seconds via Eight Persistence Points

Researchers at Sucuri have analyzed the SC malware targeting WordPress sites, which rapidly restores any removed backdoor components through a minimum of eight interconnected persistence mechanisms. The infection hides across PHP configuration settings, hidden loaders, theme files, and plugins, with some elements executing before standard WordPress plugins load. Copies of the malicious code are also stored in the database and System V shared memory on supported servers, allowing full reinfection from surviving sources after file cleanup. The backdoor evades plugin listings, gathers site and administrator session data, deploys additional PHP code, and disables security plugins while injecting JavaScript for payment data theft in online stores. Command-and-control occurs through public Ethereum RPC gateways and smart contracts with multiple fallback channels. Sucuri warns that PHP caching of the loader directive can crash request handling if the referenced file is deleted without prior preparation, and recommends a sequenced cleanup process.

AntiMalware•Malware & Botnets

RATHat Trojan Leverages Google Gemini to Infect and Control Android Devices

The banking trojan RATHat has begun using Google Gemini as an assistant to infect Android smartphones and maintain persistence. Researchers at Cleafy report that the malware first disguises itself as a legitimate application and tricks users into granting Accessibility permissions. Once inside, RATHat activates wireless debugging, connects via ADB, and deploys a separate Go-based service running with system-level privileges. Gemini helps the trojan interpret unfamiliar Android interfaces across different versions, languages, and manufacturer skins by analyzing UI structures and suggesting the correct taps. On the attacker side, the same model processes intercepted SMS messages, evaluates bank balances, and ranks compromised devices by financial value. Since April, Cleafy has observed nearly 100 deployments of the command-and-control infrastructure, pointing to a possible malware-as-a-service model. Removing the original APK is insufficient because the Go service survives independently until reboot and can reinstall the dropped payload.

AntiMalware•Malware & Botnets

Mimbrob Malware Uses Fake Dronner App to Target Russian Military and Industrial Firms

Researchers at F6 have identified a new malware campaign dubbed Mimbrob that leverages a fake drone-tracking application called Dronner. The lure promises data on heavy Baba Yaga drones and remote mining locations but instead deploys malicious payloads aimed primarily at Russian military personnel near the front line. The malware checks system language, keyboard layouts, and interface preferences, remaining dormant or terminating if Russian or certain CIS and Romanian languages are absent. Since April 2026 the same operators have conducted phishing campaigns against Russian industrial and IT companies using FBULoader disguised as a Yandex Browser update and the RAT-Go remote access trojan. The attackers register lookalike domains of legitimate Russian enterprises to deliver fake metrology notices and court documents. While espionage appears the most probable objective, researchers have not yet obtained the final payload and therefore refrain from definitive attribution.