hacker-news · Crawled Jul 16, 2026
Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor
4 IoCs 1 Malware
Read original article ↗
AI Summary
A China-linked threat actor has resurfaced with the Daxin kernel-mode rootkit, detected in 2026 within a Taiwan-based subsidiary of a multinational high-tech manufacturer. The compromised system was also infected with a previously undocumented backdoor, Stupig, which enables pre-login SYSTEM-level command execution by masquerading as a legitimate keyboard DLL. Both malware samples were compiled in 2013, suggesting long-term stealthy persistence, with Daxin using covert C2 via hijacked TCP connections and Stupig enabling credential theft before user login. The attack highlights sophisticated, sustained cyber espionage activity targeting critical infrastructure.
AI-extracted · verify before operational use