216.73.216.233

Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor

· Published 15/07/2026 13:58

Export JSON

Essential information

Published
15/07/2026 13:58
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
backdoor china-linked espionage daxin kernel-mode rootkit keyboard-layout dll stupig taiwan targeting winlogon persistence
Related entities
2 indicators, 20 techniques (mitre), 2 malware

Description

.Daxin, a sophisticated China-linked kernel-mode rootkit first exposed in 2022, was discovered operating on a Taiwan manufacturing firm's network in 2026. The malware was found alongside .Stupig, a previously unknown that uses a novel technique involving a Trojanized keyboard-layout DLL loaded by winlogon.exe, enabling command execution as System from the Windows logon screen without authentication. Both samples carry compile timestamps from early 2013, but the compromised host only began reporting telemetry in May 2026, suggesting a possible 13-year undetected intrusion. The victim was a Taiwan-based subsidiary of a multinational high-tech manufacturer. Daxin's defining characteristic is its ability to hijack legitimate TCP connections for command-and-control traffic, making it exceptionally difficult to detect through conventional network monitoring.

External references