Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor
ID: cc4b8a5b-1c49-5ed7-91d6-1359d689ac8e
STIX ID: report--cc4b8a5b-1c49-5ed7-91d6-1359d689ac8e
Feed Name: security.com
Threat Score
Symantec discovered Backdoor.Daxin active on a compromised host in Taiwan in May 2026 alongside a previously undocumented DLL backdoor, Backdoor.Stupig, which provides pre-authentication SYSTEM command execution by registering as a keyboard-layout provider; both tools carry 2013 compile timestamps and their co-deployment suggests a long-running, China-linked espionage operation against a Taiwan-based high‑tech subsidiary, with file IOCs and detection guidance provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
