logo

Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor

ID: cc4b8a5b-1c49-5ed7-91d6-1359d689ac8e

STIX ID: report--cc4b8a5b-1c49-5ed7-91d6-1359d689ac8e

Feed Name: security.com

Threat Score
92/100

Date Published: 2026-07-15

Date Updated: 2026-07-20

Author: Threat Hunter Team

...
...

Symantec discovered Backdoor.Daxin active on a compromised host in Taiwan in May 2026 alongside a previously undocumented DLL backdoor, Backdoor.Stupig, which provides pre-authentication SYSTEM command execution by registering as a keyboard-layout provider; both tools carry 2013 compile timestamps and their co-deployment suggests a long-running, China-linked espionage operation against a Taiwan-based high‑tech subsidiary, with file IOCs and detection guidance provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.