logo

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor

ID: 011230f3-9530-596c-9676-e43422cc7049

STIX ID: report--011230f3-9530-596c-9676-e43422cc7049

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-07-16

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

Symantec and Carbon Black reported the 2026 discovery of Daxin (a kernel-mode rootkit) and a newly observed backdoor named Stupig on a Taiwan-based high-tech manufacturer's host; both carry 2013 compile timestamps and are suspected components of a long-running China-linked espionage operation. Daxin hijacks legitimate inbound TCP connections and supports multi-hop communications (enabling reach into isolated segments), while Stupig registers as a keyboard-layout provider to load into winlogon.exe and allow SYSTEM-level command execution from the Windows logon screen. The likely initial vector is an outdated Digiwin SSO using EOL JDKs, and analysts also observed suspected actor use of Anthropic Claude Code and DeepSeek models to automate intrusion tasks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.