C
月内に
Windows向けの新種のバックドア「Sleepwalker」
📌 一言でいうと
Windows向けの新種のバックドア「Sleepwalker」が発見されました。このマルウェアはESET Management Agent (ERAAgent.exe) のDLLサイドローディング手法を用いて、システムライブラリのdpapi.dllに偽装してメモリ内に潜伏します。特筆すべきは、特定のネットワークパケットを受信するまで非アクティブ状態で待機し、独自のコマンド言語で制御される点です。
🔍該当判定
- 社内で『ESET Management Agent』を導入して利用している
- Windows PCにおいて、ESET製品の管理用プログラム(ERAAgent.exe)が動作している
- ESET製品を導入しており、かつ不審なDLLファイル(dpapi.dll)がプログラムフォルダに混入していないか確認が必要な環境である
上記いずれにも該当しない → 静観でOK
✅該当時の対応
1. ESET Management Agentのインストールディレクトリに不審なdpapi.dllが存在しないか確認してください。 2. 署名のないDLLの読み込みを制限するセキュリティ設定を検討してください。 3. ネットワーク監視において、不審な外部からのパケット流入を検知する体制を整えてください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Windowsバックドア「Sleepwalker」の検知と対策について
お疲れさまです。新種のバックドア「Sleepwalker」に関する情報共有です。
■ 概要
ESET Management Agent (ERAAgent.exe) を悪用したDLLサイドローディングにより、システムライブラリ「dpapi.dll」に偽装してメモリ内に潜伏するマルウェアです。特定のネットワークパケットを受信するまで待機し、検知を回避する特性を持っています。
■ 影響範囲
- ESET Management Agent を利用している Windows 環境
■ 対応手順
1. ERAAgent.exe と同一ディレクトリに、署名のない不審な dpapi.dll が配置されていないかスキャンを実施してください。
2. EDR等のツールを用いて、ERAAgent.exe による不審なネットワーク通信やメモリ動作を監視してください。
■ 参考情報
- xakep (Dominik Reichel's research)
対応優先度: 中
対応期限: 速やかに確認
お疲れさまです。新種のバックドア「Sleepwalker」に関する情報共有です。
■ 概要
ESET Management Agent (ERAAgent.exe) を悪用したDLLサイドローディングにより、システムライブラリ「dpapi.dll」に偽装してメモリ内に潜伏するマルウェアです。特定のネットワークパケットを受信するまで待機し、検知を回避する特性を持っています。
■ 影響範囲
- ESET Management Agent を利用している Windows 環境
■ 対応手順
1. ERAAgent.exe と同一ディレクトリに、署名のない不審な dpapi.dll が配置されていないかスキャンを実施してください。
2. EDR等のツールを用いて、ERAAgent.exe による不審なネットワーク通信やメモリ動作を監視してください。
■ 参考情報
- xakep (Dominik Reichel's research)
対応優先度: 中
対応期限: 速やかに確認
Subject: [Intel] Windows Backdoor 'Sleepwalker' Detection and Mitigation
Dear Team,
We are sharing information regarding a newly discovered Windows backdoor named 'Sleepwalker'.
■ Overview
Sleepwalker employs DLL side-loading via ERAAgent.exe (ESET Management Agent) to masquerade as the system library 'dpapi.dll'. It remains dormant in memory until it receives a specific network packet, making it highly evasive.
■ Scope
- Windows environments running ESET Management Agent.
■ Mitigation Steps
1. Scan the ERAAgent.exe installation directory for any unsigned or suspicious dpapi.dll files.
2. Use EDR tools to monitor ERAAgent.exe for anomalous network traffic or memory behavior.
■ Reference
- xakep (Dominik Reichel's research)
Priority: Medium
Deadline: Immediate review
Dear Team,
We are sharing information regarding a newly discovered Windows backdoor named 'Sleepwalker'.
■ Overview
Sleepwalker employs DLL side-loading via ERAAgent.exe (ESET Management Agent) to masquerade as the system library 'dpapi.dll'. It remains dormant in memory until it receives a specific network packet, making it highly evasive.
■ Scope
- Windows environments running ESET Management Agent.
■ Mitigation Steps
1. Scan the ERAAgent.exe installation directory for any unsigned or suspicious dpapi.dll files.
2. Use EDR tools to monitor ERAAgent.exe for anomalous network traffic or memory behavior.
■ Reference
- xakep (Dominik Reichel's research)
Priority: Medium
Deadline: Immediate review