SLEEPWALKER Backdoor Uses Magic Packet, DLL Side-Loading and In-Memory Shellcode Execution

A newly documented Windows backdoor named SLEEPWALKER combines passive network monitoring, DLL side-loading, and encrypted bytecode to remain dormant until attackers deliver a precisely crafted trigger packet. The malware does not beacon to a conventional command-and-control server, making it particularly difficult to identify through outbound-traffic monitoring alone. The 59,904-byte unsigned file masquerades as Microsoft’s dpapi.dll […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: