Threat Intelligence

New 'SLEEPWALKER' Backdoor Hides Silently Until a Secret Signal Activates It

The Hacker News · 26 Aug 2026
Key Takeaway Ensure your business monitors unusual outbound network traffic and keeps endpoint protection updated, since dormant malware like SLEEPWALKER can hide undetected until remotely activated.

A previously unknown Windows backdoor named SLEEPWALKER has been identified by an independent malware researcher. What makes it notable is its patience: the malware sits inactive in a computer's memory, doing nothing suspicious, until it receives a single, specifically crafted network packet. Only then does it spring into action, running commands through a custom 23-instruction system built specifically for this malware.

The malicious file is a 59,904-byte, 64-bit Windows DLL (dynamic-link library) that is unsigned, meaning it lacks the digital certificate that legitimate software typically carries. It is designed to be 'side-loaded' — a technique where malware is disguised or bundled alongside a legitimate application so it runs without raising obvious red flags, often exploiting how Windows loads supporting files for trusted programs.

Because SLEEPWALKER remains dormant until triggered remotely, it can be difficult for standard antivirus tools to detect through normal behaviour monitoring alone. This 'wait and listen' approach is designed to evade automated security scans and human analysts who may not observe any active malicious behaviour during initial investigation.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.