logo

Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network

ID: f347d33f-3388-50b8-b07c-186790eb7fb5

STIX ID: report--f347d33f-3388-50b8-b07c-186790eb7fb5

Feed Name: Security Affairs

Threat Score
90/100

Date Published: 2026-07-18

Date Updated: 2026-07-19

Author: Pierluigi Paganini

...
...

Symantec found the China-linked Daxin kernel rootkit and a novel Stupig backdoor on a Taiwanese manufacturer's host; both appear compiled in 2013 but produced telemetry in 2026, indicating a potential 13-year undetected intrusion. Daxin provides stealthy multi-hop C2 by hijacking existing TCP connections (useful for isolated networks), while Stupig masquerades as a keyboard-layout DLL loaded into winlogon.exe to execute SYSTEM-level commands pre-authentication—highlighting sophisticated, long-lived nation-state techniques and significant detection gaps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.