Newly SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode
A previously unknown Windows backdoor called SLEEPWALKER has been discovered by an independent researcher, featuring a dormant-until-triggered mechanism that activates only upon receipt of a specially crafted network packet. Once activated, the unsigned 64-bit DLL executes commands using a custom 23-instruction bytecode language, designed for side-loading into legitimate processes. This stealthy approach allows the malware to remain undetected in memory until explicitly triggered by an attacker.
Threat actors are impersonating employers on the Indeed job board to distribute malicious Android applications disguised as interview tools to unsuspecting job seekers. Once installed, these fake apps deliver spyware capable of compromising victim devices. This campaign exploits the trust job applicants place in legitimate recruitment platforms to gain initial access.
A malware campaign discovered by Cato Networks exploits sponsored search ads to direct macOS users to a fake OpenAI Codex download page, where victims are socially engineered into pasting malicious commands directly into Terminal. The attack uses a variation of the ClickFix technique, which manipulates users into executing the infection themselves rather than opening a malicious file, with the campaign beginning through sponsored search results for queries like "codex macos download."
Researchers have identified a novel command-and-control technique where threat actors exploit FTP banners as dead drop resolvers to deliver two previously unreported RATs named E4del and PINHOLE. This approach leverages legitimate FTP services to obscure malware communications and point to additional C2 infrastructure while evading detection.
Kaspersky researchers have identified the first malware specifically designed to target car head units, which has been enlisted into the BadBox botnet infrastructure. The discovery represents a significant expansion of botnet operations into automotive systems, with the malware already compromising millions of devices across the network.