You don't want this Sleepwalker backdoor on your Windows machine

alimac

Well-known member
VIP
Like a sleeper cell awaiting activation, a never-before-seen Windows backdoor dubbed Sleepwalker waits silently in memory for one specifically crafted network packet to wake it up and deliver commands using the malware's 23-instruction language. The commands can do everything from running code directly in memory to moving data off the computer.

https://www.theregister.com/securit...lker-backdoor-on-your-windows-machine/5292021

search for the mentioned DLL and ESET binaries and check the signatures - the article mentions the files are not signed. But the easiest is to look for the ESET exe running in memory and not being signed by ESET, I think. This is more relevant for servers that can receive network packets, as the article mentions, or machines that don't necessarily have an active user on them who would occasionally check the task manager or process table.
 
Back
Top