SLEEPWALKER: New Windows malware lies dormant until awakened by custom network signal
New Windows malware SLEEPWALKER hides as ESET agent and activates only after a custom network signal; no active campaigns found.
SLEEPWALKER masquerades as a legitimate component of ESET's Management Agent, allowing it to run from within a trusted application and evade security software. It listens for a custom signal, and upon receiving it, the signal can instruct the malware to schedule activities, communicate with other systems, receive additional programs, or execute code.
The sample was submitted to VirusTotal sometime last year, Reichel said. It was not found in any active campaigns, and there are no confirmed victims, industries, countries, or organizations associated with the sample. Reichel also noted that it is unknown how the malware initially entered the environment, who runs it, and what additional tools may have accompanied it.
Reichel described the code as 'rough around the edges' with several weaknesses, suggesting it may be a work in progress. He is not sure if newer variants exist in the wild. Given the nature of the malware, he believes it was most likely designed by nation-states for targeted attacks rather than indiscriminate campaigns.