Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor
Backdoor.Daxin, a sophisticated China-linked kernel-mode rootkit first exposed in 2022, was discovered operating on a Taiwan manufacturing firm's network in 2026. The malware was found alongside Backdoor.Stupig, a previously unknown backdoor that uses a novel technique involving a Trojanized keyboard-layout DLL loaded by winlogon.exe, enabling command execution as System from the Windows logon screen without authentication. Both samples carry compile timestamps from early 2013, but the compromised host only began reporting telemetry in May 2026, suggesting a possible 13-year undetected intrusion. The victim was a Taiwan-based subsidiary of a multinational high-tech manufacturer. Daxin's defining characteristic is its ability to hijack legitimate TCP connections for command-and-control traffic, making it exceptionally difficult to detect through conventional network monitoring.
AI Analysis
Technical Summary
The threat involves two sophisticated malware families: Backdoor.Daxin, a kernel-mode rootkit linked to China, and Backdoor.Stupig, a novel backdoor using a Trojanized keyboard-layout DLL loaded by the Windows winlogon.exe process. Daxin's key feature is hijacking legitimate TCP connections for stealthy command-and-control communication. Stupig enables command execution as the SYSTEM user from the Windows logon screen without authentication. Both malware samples have compile timestamps from early 2013, but telemetry from the compromised host only began in May 2026, suggesting a long-term undetected intrusion. The infection was discovered on a Taiwan manufacturing firm's network, specifically a subsidiary of a multinational high-tech company. This malware campaign demonstrates advanced persistence and evasion techniques, complicating detection and mitigation efforts.
Potential Impact
The malware enables persistent, stealthy remote access and command execution with SYSTEM privileges on affected Windows hosts. Daxin's hijacking of legitimate TCP connections for command-and-control traffic makes network-based detection challenging. Stupig's ability to execute commands from the Windows logon screen without authentication increases the risk of unauthorized system control. The long undetected presence (potentially 13 years) indicates a significant compromise of confidentiality and integrity for the victim organization. The targeting of a Taiwan-based high-tech manufacturing subsidiary suggests potential espionage motives.
Mitigation Recommendations
No official patch or remediation guidance is provided in the available data. Given the advanced and stealthy nature of the malware, organizations should conduct thorough endpoint and network forensic investigations to identify and remove infections. Monitoring for unusual DLL loads by winlogon.exe and anomalous TCP connection hijacking may help detect these threats. Because no patch or fix is indicated, organizations should apply defense-in-depth strategies focused on detection and incident response. Patch status is not yet confirmed — check vendor advisories and threat intelligence updates for any emerging remediation guidance.
Affected Countries
Taiwan
Indicators of Compromise
- hash: 49c827cf48efb122a9d6fd87b426482b7496ccd4a2dbca31ebbf6b2b80c98530
- hash: 5bb5cffda4647940919a185df37aab2aef71ca3010a6c1d05bdcc8bc8fb3af3f
Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor
Description
Backdoor.Daxin, a sophisticated China-linked kernel-mode rootkit first exposed in 2022, was discovered operating on a Taiwan manufacturing firm's network in 2026. The malware was found alongside Backdoor.Stupig, a previously unknown backdoor that uses a novel technique involving a Trojanized keyboard-layout DLL loaded by winlogon.exe, enabling command execution as System from the Windows logon screen without authentication. Both samples carry compile timestamps from early 2013, but the compromised host only began reporting telemetry in May 2026, suggesting a possible 13-year undetected intrusion. The victim was a Taiwan-based subsidiary of a multinational high-tech manufacturer. Daxin's defining characteristic is its ability to hijack legitimate TCP connections for command-and-control traffic, making it exceptionally difficult to detect through conventional network monitoring.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The threat involves two sophisticated malware families: Backdoor.Daxin, a kernel-mode rootkit linked to China, and Backdoor.Stupig, a novel backdoor using a Trojanized keyboard-layout DLL loaded by the Windows winlogon.exe process. Daxin's key feature is hijacking legitimate TCP connections for stealthy command-and-control communication. Stupig enables command execution as the SYSTEM user from the Windows logon screen without authentication. Both malware samples have compile timestamps from early 2013, but telemetry from the compromised host only began in May 2026, suggesting a long-term undetected intrusion. The infection was discovered on a Taiwan manufacturing firm's network, specifically a subsidiary of a multinational high-tech company. This malware campaign demonstrates advanced persistence and evasion techniques, complicating detection and mitigation efforts.
Potential Impact
The malware enables persistent, stealthy remote access and command execution with SYSTEM privileges on affected Windows hosts. Daxin's hijacking of legitimate TCP connections for command-and-control traffic makes network-based detection challenging. Stupig's ability to execute commands from the Windows logon screen without authentication increases the risk of unauthorized system control. The long undetected presence (potentially 13 years) indicates a significant compromise of confidentiality and integrity for the victim organization. The targeting of a Taiwan-based high-tech manufacturing subsidiary suggests potential espionage motives.
Defensive Guidance
No official patch or remediation guidance is provided in the available data. Given the advanced and stealthy nature of the malware, organizations should conduct thorough endpoint and network forensic investigations to identify and remove infections. Monitoring for unusual DLL loads by winlogon.exe and anomalous TCP connection hijacking may help detect these threats. Because no patch or fix is indicated, organizations should apply defense-in-depth strategies focused on detection and incident response. Patch status is not yet confirmed — check vendor advisories and threat intelligence updates for any emerging remediation guidance.
Affected Countries
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.security.com/blog-post/daxin-returns-stupig"]
- Adversary
- null
- Pulse Id
- 6a5775d3b8fe983226594b7c
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hash49c827cf48efb122a9d6fd87b426482b7496ccd4a2dbca31ebbf6b2b80c98530 | — | |
hash5bb5cffda4647940919a185df37aab2aef71ca3010a6c1d05bdcc8bc8fb3af3f | — |
Threat ID: 6a58000568715ace438b1881
Added to database: 07/15/2026, 21:47:49 UTC
Last enriched: 07/15/2026, 22:03:18 UTC
Last updated: 08/15/2026, 13:31:06 UTC
Views: 164
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.