logo

Hackers Can Type a Secret Username at the Windows Login Screen to Open a SYSTEM Shell

ID: 7c246914-fc7f-50fa-956e-5abb4502844c

STIX ID: report--7c246914-fc7f-50fa-956e-5abb4502844c

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Tushar Subhra Dutta

...
...

**Executive summary:** Symantec investigators uncovered two stealthy Windows backdoors on a Taiwan-based high‑tech subsidiary: Backdoor.Stupig, which registers as keyboard support to execute commands as SYSTEM at the login screen and capture credentials, and Daxin, a kernel‑level backdoor used for long‑running espionage that blends into legitimate traffic; the report provides IoCs, detection recommendations (inspect winlogon DLLs, keyboard-layout registrations, failed logons with 'stupig' prefixes, and replace unsupported Java SSO components), and notes likely China-linked persistent activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.