← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 27, 2026 · 06:43via CyberPress

SLEEPWALKER Backdoor Uses SMB, ICMP, DNS and VMware VMCI for Covert Communications

Brief

Researchers have uncovered a previously unknown Windows backdoor named SLEEPWALKER that can receive attacker commands through covert channels including raw network packets, DNS queries , SMB named pipes, ICMP ping traffic, and VMware’s VMCI communication layer.

The malware is designed to remain dormant and avoid the usual signs of compromise. It does not contact a hard-coded command-and-control server, open a default listening port, or include an embedded final-stage payload.

Instead, it waits for a specially crafted and encrypted trigger packet before activating. SLEEPWALKER was found as an unsigned 64-bit DLL impersonating Microsoft’s dpapi. dll .

The sample copies version information from ESET Management Agent and is built to be side-loaded by ERAAgent. exe , the ESET Management Agent executable.

Read more on CyberPress