Stealthy Daxin Malware Hijacks Legitimate TCP Connections to Evade C2 Detection
ID: fc8921b8-68fe-5635-85c6-6f7be62ceb0e
STIX ID: report--fc8921b8-68fe-5635-85c6-6f7be62ceb0e
Feed Name: Cyber Press
Symantec researchers discovered an active intrusion (May 2026) against a Taiwan-based subsidiary that used the advanced Daxin kernel-mode backdoor—capable of hijacking legitimate TCP connections—and a newly identified DLL backdoor, Stupig, which achieves persistence by registering as a keyboard layout to load into winlogon.exe and execute SYSTEM commands from the logon screen; the report includes IOCs (SHA-256 hashes and file paths), detection guidance, and links the activity to a China-associated espionage operation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
