Daxin Malware and New Backdoor Stupig Resurface in Taiwan
ID: 212f1a7b-c661-5e81-b005-a624c533f6b4
STIX ID: report--212f1a7b-c661-5e81-b005-a624c533f6b4
Feed Name: ThreatCluster
Daxin, a sophisticated backdoor associated with Chinese actors, reappeared in Taiwan in May 2026 targeting a multinational high‑tech manufacturer; it hijacks legitimate TCP connections for command-and-control. A newly identified backdoor, Stupig, exhibits novel persistence methods; both share early‑2013 compile timestamps suggesting a shared developer. Initial access likely exploited an outdated Digiwin SSO using obsolete Java, and the compromised host showed no prior telemetry, indicating long-term covert espionage operations against strategic targets in Taiwan.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
