logo

China-Linked Daxin Backdoor Resurfaces in Taiwan Alongside New STUPIG SYSTEM-Level Malware

ID: ffc434b2-c753-518b-bede-f255fcd78a1e

STIX ID: report--ffc434b2-c753-518b-bede-f255fcd78a1e

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Mayura Kathir

...
...

Symantec reported a China-linked espionage intrusion targeting a Taiwan-based subsidiary where operators deployed the advanced Daxin kernel-mode backdoor (srt64.sys) and a companion Windows backdoor, Backdoor.Stupig (a.dll / kbdus1.dll disguised as a keyboard-layout DLL). Daxin hijacks inbound TCP sessions to create encrypted C2 with minimal outbound noise while Stupig is loaded into winlogon.exe to allow pre-auth SYSTEM command execution via specially prefixed usernames; investigators noted decade-old compile timestamps, possible long dwell, and provided SHA-256 file indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.