Hackers Can Type a Secret Username at the Windows Login Screen to Open a SYSTEM Shell
ID: 7c246914-fc7f-50fa-956e-5abb4502844c
STIX ID: report--7c246914-fc7f-50fa-956e-5abb4502844c
Feed Name: cybersecurityNews.com
**Executive summary:** Symantec investigators uncovered two stealthy Windows backdoors on a Taiwan-based high‑tech subsidiary: Backdoor.Stupig, which registers as keyboard support to execute commands as SYSTEM at the login screen and capture credentials, and Daxin, a kernel‑level backdoor used for long‑running espionage that blends into legitimate traffic; the report provides IoCs, detection recommendations (inspect winlogon DLLs, keyboard-layout registrations, failed logons with 'stupig' prefixes, and replace unsupported Java SSO components), and notes likely China-linked persistent activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
