• New Windows malware lays dormant until a custom command activates

    From TechnologyDaily@1337:1/100 to All on Tuesday, August 25, 2026 17:15:24
    New Windows malware lays dormant until a custom command activates it like a sleeper agent

    Date:
    Tue, 25 Aug 2026 16:10:00 +0000

    Description:
    No one knows who built it and to what end.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Researcher Dominik Reichel
    found SLEEPWALKER , a silent malware implant disguised as ESETs agent It contains no malicious code, activates only after receiving crafted network signals Likely a nationstate project targeting specific victims; no active campaigns confirmed yet Security researchers discovered a new and rather unusual piece of malware.

    Most malware come with a built-in, pre-defined set of tools and features: system fingerprinting, network mapping, data exfiltration, keylogging, screenshots, tapping into the camera and microphone. When they infect a machine, they first try to phone home using the devices internet connection and await instructions on which of the features to use. But security researcher Dominik Reichel found something entirely different: a piece of malware not having any of the above, designed to remain almost completely silent until being woken up. He named it SLEEPWALKER. Latest Videos From TechRadar Watch full video here: No active campaigns This implant has no malicious code, and therefore nothing that would get flagged by security software. It hides in plain sight, masquerading as a legitimate Windows component for ESETs Management Agent. This allows it to run from within a trusted app, instead of being a standalone program that could invite
    scrutiny.

    SLEEPWALKER listens to network traffic for a specially crafted signal, waking up only when it is received. That signal also teaches the malware what it can do - schedule different activities, communicate with other systems, receive additional programs, and even execute code. You may like Dangerous new GoSerpent malware is apparently on the hunt for government secrets This macOS malware can avoid AI analysis with gaslighting prompts hidden inside its architecture Experts warn hackers are using AI chatbots to write malware
    using natural language

    The malware was submitted to VirusTotal sometime last year, Reichel said. It was not found in any active campaigns, and there are no confirmed victims, industries, countries, or organizations associated with the sample. Reichel also stressed that its unknown how the malware initially entered the
    reporters environment, who runs it, and what additional tools may have accompanied it.

    He also said that the code is somewhat rough around the edges. Despite its unusual design, it comes with several weaknesses, which might suggest that SLEEPWALKER was a work in progress. He doesnt know if there are newer
    variants in the wild, though. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

    Still, given the nature of the malware, Reichel doesnt think it was built for indiscriminate attacks. Instead, it was most likely designed by nation-states with specific targets in mind.

    Via The Register The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/new-windows-malware-lays-dormant-until- a-custom-command-activates-it-like-a-sleeper-agent


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)