The SLEEPWALKER backdoor is a new, highly sophisticated Windows malware that lies completely dormant in memory until it receives a specially crafted network packet — at which point it executes commands written in a unique 23-instruction bytecode language . Independent malware researcher Dominik Reichel , a former member of Palo Alto Networks Unit 42 , has documented this previously unknown implant for the first time , revealing a highly targeted and well-funded cyberespionage operation.

The sample analyzed is an unsigned 64-bit Windows DLL measuring 59,904 bytes , designed to be loaded via DLL side-loading into the ERAAgent.exe process , the ESET Management Agent executable . The file mimics Microsoft 's dpapi.dll , exporting the same seven data protection functions as the genuine system library, and also carries version information copied from the ESET Management Agent . This camouflage technique makes it extremely difficult to detect by monitoring tools.
One of the most striking features of SLEEPWALKER is the complete absence of embedded domains, IP addresses, or URLs within the file. The backdoor does not make any outbound connections, allowing an infected system to appear clean to monitoring tools that check for connections to known malicious infrastructure. This feature makes it particularly dangerous in environments with strict network monitoring.
See also: Zbtlink Routers: Backdoor in 20+ models opens root shell
How the SLEEPWALKER Backdoor Works in Memory
The built-in SLEEPWALKER configuration is decrypted with AES-256-CCM in a single command that directs the backdoor to listen to each network interface indefinitely, waiting for the specific trigger packet. The listener records all traffic passing through each monitored interface, including traffic destined for other machines. This means that a gateway, a VPN server , or a host bridging two network segments could intercept a trigger intended for a different machine.
The commands are delivered as bytecode rather than readable text, making it extremely difficult to recover the encryption key. The opcodes are generated in a format unique to that file. Reichel noted that this approach is indicative of a targeted, well-funded operation rather than an opportunistic attack. The analysis was based on a single binary provided without a collection context, and the researcher was unable to attribute the sample to any known threat actor.
SLEEPWALKER checks the host process name, not its signature or path. Writing the file to the appropriate directory requires local administrator , which the operator must already have, while the backdoor relies on the host process's security framework rather than acquiring those privileges autonomously. This means that it acts as a post-compromise implant rather than an initial entry point.

The 23 SLEEPWALKER commands and transfer methods
SLEEPWALKER 's 23 commands cover task scheduling, various data movement methods, incremental file delivery with SHA-256 hash verification before execution, and direct code execution in memory. They use six transport methods : TCP , UDP , ICMP , SMB named pipes with credentialed lateral movement, raw promiscuous capture , and the VMware Virtual Machine Communication Interface (VMCI) . It is worth noting that none of the commands write to disk, so any data expected to be found on a compromised system must be placed there by another component.
The use of VMCI is particularly notable: VMCI traffic passes through the virtualization layer instead of a network adapter , meaning that a packet capture between two machines would miss it entirely. The UNC3886 team used VMCI sockets for persistence between compromised ESXi hosts and their virtual machines in attacks documented by Mandiant . This technical similarity does not prove a connection, but it does suggest that the creators of SLEEPWALKER are well-versed in advanced evasion techniques.
See also: FlutterShell Backdoor Spreads on macOS via Malicious Google and YouTube Ads
The DLL side-loading mechanism is the backdoor's only persistence mechanism, with the DLL being reloaded every time the ESET Management Agent service starts . This side-loading is based on the Windows DLL search sequence and not a flaw in ESET 's software , meaning there is nothing to patch . The response to a confirmed infection includes incident response and a full system rebuild.
Why the SLEEPWALKER Backdoor is so difficult to detect
SLEEPWALKER's architecture is designed to be as stealthy as possible. The absence of outbound connections, the use of bytecode instead of readable instructions, the emulation of a legitimate system library, and the activation only via a specially crafted network packet create an extremely difficult detection profile. Traditional EDR and SIEM that rely on monitoring outbound traffic or known indicators of compromise (IoC) would be unable to detect this implant.
Additionally, the fact that SLEEPWALKER never writes to disk during execution means that forensic analysis after an incident will find minimal traces of activity. The use of SHA-256 to verify files before execution also suggests that its creators have taken steps to prevent the execution of malicious code, which reveals a high level of professionalism. According to The Hacker News, analysis of the sample revealed that this is one of the most sophisticated backdoors documented in recent times.
See also: Alibaba bans Claude Code due to alleged backdoor risk
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

For organizations using ESET Management Agent or similar security management tools, the SLEEPWALKER discovery highlights the need to regularly check the integrity of DLL in installation directories. Monitoring for abnormal loads DLL, especially those that mimic system libraries, is a critical defense measure. Additionally, analyzing network traffic at the packet capture — and not just the flow level — can help identify unusual packets that could be triggers.
