New Windows malware lays dormant until a custom command activates it like a sleeper agent

https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-2560-80.jpg
  • Researcher Dominik Reichel found SLEEPWALKER, a silent malware implant disguised as ESET’s agent
  • It contains no malicious code, activates only after receiving crafted network signals
  • Likely a nation‑state project targeting specific victims; no active campaigns confirmed yet

Security researchers discovered a new and rather unusual piece of malware.

Most malware come with a built-in, pre-defined set of tools and features: system fingerprinting, network mapping, data exfiltration, keylogging, screenshots, tapping into the camera and microphone. When they infect a machine, they first try to phone home using the device’s internet connection and await instructions on which of the features to use.

But security researcher Dominik Reichel found something entirely different: a piece of malware not having any of the above, designed to remain almost completely silent until being “woken up”. He named it SLEEPWALKER.

No active campaigns

This implant has no malicious code, and therefore nothing that would get flagged...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE