CyberSecurityBoardThreat Intel · CVEs · Products
Malware

SLEEPWALKER Backdoor: Technical Analysis

August 26, 2026

SLEEPWALKER is a Windows backdoor that remains dormant until receiving a crafted network packet. It executes commands in a custom 23-instruction bytecode language and uses DLL side-loading via ESET Management Agent. It supports multiple transports including TCP, UDP, ICMP, SMB named pipes, raw capture, and VMware VMCI. No outbound connections are made, and it uses AES-256-CCM for configuration decryption.