The PolySwarm Blog

Analyze suspicious files and URLs, at scale, millions of times per day. Get real-time threat intel from a crowdsourced network of security experts and antivirus companies competing to protect you.

SLEEPWALKER: Passive Backdoor Awakens Only When Attackers Call

Aug 31, 2026, 2:54:48 PM / by The Hivemind posted in Threat Bulletin, DLL side-loading, passive backdoor, ESET Management Agent malware, ERAAgent.exe, SLEEPWALKER malware

0 Comments

Executive Summary

SLEEPWALKER is a novel passive Windows backdoor. The malware is designed for DLL side-loading into the ESET Management Agent process ERAAgent.exe and does not autonomously beacon or contain fixed C2 infrastructure. Instead, SLEEPWALKER remains dormant until receiving a specially crafted network packet, then decrypts and executes attacker-supplied bytecode through a custom 23-instruction command language supporting scheduling, multiple communications mechanisms, staged payload delivery, lateral movement, and in-memory code execution.

Read More

Subscribe to Email Updates

Lists by Topic

see all

Posts by Topic

See all

Recent Posts