A new malware called SLEEPWALKER remains inactive until it receives a specific network signal

Security researchers have uncovered a new and relatively uncommon type of malware. Most malware comes with a predefined set of tools and capabilities: system fingerprinting, network mapping, data exfiltration, keystroke logging, screen captures, and access to the camera and microphone.

How does SLEEPWALKER work?

The SLEEPWALKER malware contains no malicious code, and therefore there is nothing to trigger security software alerts. It hides in plain sight, disguised as a legitimate Windows component for the ESET Admin Agent. This enables it to run from within a trusted application rather than as an independent program that could draw attention.

  • SLEEPWALKER monitors network traffic for a specific signal.
  • Once it receives the signal, the malware activates and can schedule various activities, communicate with other systems, receive additional payloads, and execute code.

Is SLEEPWALKER a nation-state project?

Security researcher Dominik Reichel suggests that SLEEPWALKER was not designed for indiscriminate attacks but likely created for specific objectives. The malware was submitted to VirusTotal some time ago, but it has not appeared in active campaigns and there are no confirmed victims.

Source: TechRadar News

Rate this article

Current rating: 0.00/5 from 0 votes.

Comments

No approved comments yet. Be the first to share your thoughts.

T
Written by

TechNodo Editorial

Independent technology reporting, practical analysis and product guidance for curious readers.