Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor

0
Medium
Published: 07/15/2026 (07/15/2026, 11:58:11 UTC)
Source: AlienVault OTX General

Description

Backdoor.Daxin, a sophisticated China-linked kernel-mode rootkit first exposed in 2022, was discovered operating on a Taiwan manufacturing firm's network in 2026. The malware was found alongside Backdoor.Stupig, a previously unknown backdoor that uses a novel technique involving a Trojanized keyboard-layout DLL loaded by winlogon.exe, enabling command execution as System from the Windows logon screen without authentication. Both samples carry compile timestamps from early 2013, but the compromised host only began reporting telemetry in May 2026, suggesting a possible 13-year undetected intrusion. The victim was a Taiwan-based subsidiary of a multinational high-tech manufacturer. Daxin's defining characteristic is its ability to hijack legitimate TCP connections for command-and-control traffic, making it exceptionally difficult to detect through conventional network monitoring.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/15/2026, 22:03:18 UTC

Technical Analysis

The threat involves two sophisticated malware families: Backdoor.Daxin, a kernel-mode rootkit linked to China, and Backdoor.Stupig, a novel backdoor using a Trojanized keyboard-layout DLL loaded by the Windows winlogon.exe process. Daxin's key feature is hijacking legitimate TCP connections for stealthy command-and-control communication. Stupig enables command execution as the SYSTEM user from the Windows logon screen without authentication. Both malware samples have compile timestamps from early 2013, but telemetry from the compromised host only began in May 2026, suggesting a long-term undetected intrusion. The infection was discovered on a Taiwan manufacturing firm's network, specifically a subsidiary of a multinational high-tech company. This malware campaign demonstrates advanced persistence and evasion techniques, complicating detection and mitigation efforts.

Potential Impact

The malware enables persistent, stealthy remote access and command execution with SYSTEM privileges on affected Windows hosts. Daxin's hijacking of legitimate TCP connections for command-and-control traffic makes network-based detection challenging. Stupig's ability to execute commands from the Windows logon screen without authentication increases the risk of unauthorized system control. The long undetected presence (potentially 13 years) indicates a significant compromise of confidentiality and integrity for the victim organization. The targeting of a Taiwan-based high-tech manufacturing subsidiary suggests potential espionage motives.

Defensive Guidance

No official patch or remediation guidance is provided in the available data. Given the advanced and stealthy nature of the malware, organizations should conduct thorough endpoint and network forensic investigations to identify and remove infections. Monitoring for unusual DLL loads by winlogon.exe and anomalous TCP connection hijacking may help detect these threats. Because no patch or fix is indicated, organizations should apply defense-in-depth strategies focused on detection and incident response. Patch status is not yet confirmed — check vendor advisories and threat intelligence updates for any emerging remediation guidance.

Affected Countries

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.security.com/blog-post/daxin-returns-stupig"]
Adversary
null
Pulse Id
6a5775d3b8fe983226594b7c
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hash49c827cf48efb122a9d6fd87b426482b7496ccd4a2dbca31ebbf6b2b80c98530
hash5bb5cffda4647940919a185df37aab2aef71ca3010a6c1d05bdcc8bc8fb3af3f

Threat ID: 6a58000568715ace438b1881

Added to database: 07/15/2026, 21:47:49 UTC

Last enriched: 07/15/2026, 22:03:18 UTC

Last updated: 08/15/2026, 13:31:06 UTC

Views: 164

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses