China-Linked Daxin Backdoor Resurfaces in Taiwan Alongside New STUPIG SYSTEM-Level Malware
ID: ffc434b2-c753-518b-bede-f255fcd78a1e
STIX ID: report--ffc434b2-c753-518b-bede-f255fcd78a1e
Feed Name: GBHackers
Symantec reported a China-linked espionage intrusion targeting a Taiwan-based subsidiary where operators deployed the advanced Daxin kernel-mode backdoor (srt64.sys) and a companion Windows backdoor, Backdoor.Stupig (a.dll / kbdus1.dll disguised as a keyboard-layout DLL). Daxin hijacks inbound TCP sessions to create encrypted C2 with minimal outbound noise while Stupig is loaded into winlogon.exe to allow pre-auth SYSTEM command execution via specially prefixed usernames; investigators noted decade-old compile timestamps, possible long dwell, and provided SHA-256 file indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
