<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Reverse Engineering on HackingPassion.com : root@HackingPassion.com-[~]</title><link>https://hackingpassion.com/tags/reverse-engineering/</link><description>Recent content in Reverse Engineering on HackingPassion.com : root@HackingPassion.com-[~]</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sun, 30 Aug 2026 12:13:30 +0200</lastBuildDate><atom:link href="https://hackingpassion.com/tags/reverse-engineering/index.xml" rel="self" type="application/rss+xml"/><item><title>SLEEPWALKER Backdoor Hides in a Security Agent and Wakes Up for One Packet</title><link>https://hackingpassion.com/sleepwalker-passive-backdoor-magic-packet/</link><pubDate>Sun, 30 Aug 2026 12:13:30 +0200</pubDate><guid>https://hackingpassion.com/sleepwalker-passive-backdoor-magic-packet/</guid><description>&lt;h1 id="sleepwalker-backdoor-hides-in-a-security-agent-and-wakes-up-for-one-packet">SLEEPWALKER Backdoor Hides in a Security Agent and Wakes Up for One Packet&lt;/h1>
&lt;p>&lt;strong>5 bytes of orders sit inside a backdoor that has never once called home. It reads what crosses your network cable and waits. The security agent it hides in loads it again at each restart.&lt;/strong>&lt;/p>
&lt;p>Dominik Reichel, who used to hunt malware at Palo Alto Unit 42, published the analysis on August 24. He named it SLEEPWALKER, because that is what it does. It sits in memory and does nothing at all until one specific packet crosses the network cable, and then it wakes up and runs whatever the sender told it to run.&lt;/p></description></item></channel></rss>