← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 1, 2026 · 10:04via CyberPress

SLEEPWALKER Backdoor Hides Inside ESET Agent and Awakens Only on Network Trigger

Brief

SLEEPWALKER is a newly identified passive Windows backdoor designed to remain dormant until it receives a specially crafted network packet.

Unlike conventional backdoors that regularly contact command-and-control (C2) servers, SLEEPWALKER does not contain fixed C2 domains, IP addresses, URLs, or second-stage payloads.

The malware is designed for DLL side-loading through the ESET Management Agent process, ERAAgent. exe . The analyzed sample is an unsigned 64-bit DLL that masquerades as Microsoft’s dpapi. dll .

It carries version information copied from the legitimate ESET Management Agent , helping it blend into a trusted software environment.

Researcher Dominik Reichel discovered SLEEPWALKER and assessed that its design is more consistent with a targeted and well-resourced operation than opportunistic malware.

Read more on CyberPress