Executive Summary
In May 2026, Symantec's Threat Hunter Team identified the re-emergence of Backdoor.Daxin, a sophisticated kernel-mode rootkit previously linked to China-based threat actors, on a compromised host within a Taiwan-based subsidiary of a multinational high-tech manufacturer. Alongside Daxin, researchers discovered a novel backdoor named Stupig, which exploits a trojanized keyboard-layout DLL to execute commands with SYSTEM privileges directly from the Windows logon screen, bypassing standard authentication mechanisms. Both malware samples carry compile timestamps from early 2013, suggesting a prolonged undetected presence of up to 13 years within the victim's network. This incident underscores the persistent and evolving nature of cyber threats targeting critical infrastructure and high-tech industries. The discovery of Stupig's unique pre-authentication execution method highlights the need for continuous vigilance and advanced detection capabilities to identify and mitigate such stealthy intrusions.
Why This Matters Now
The resurgence of Daxin and the emergence of Stupig highlight the evolving sophistication of cyber threats targeting critical infrastructure. Organizations must enhance their detection and response strategies to address these advanced persistent threats effectively.
Attack Path Analysis
The attackers exploited vulnerabilities in an outdated single sign-on (SSO) portal to gain initial access to the network. They then deployed the Stupig backdoor to achieve SYSTEM-level privileges by intercepting the Windows logon process. Utilizing Daxin's capabilities, they moved laterally across the network by hijacking legitimate TCP connections. Daxin facilitated encrypted command-and-control communications by embedding within existing network traffic. The attackers likely exfiltrated sensitive data through these covert channels. The prolonged undetected presence of the malware suggests potential long-term impacts on the organization's security posture.
Kill Chain Progression
Initial Compromise
Description
Exploited vulnerabilities in an outdated single sign-on (SSO) portal to gain initial access.
MITRE ATT&CK® Techniques
Exploitation for Privilege Escalation
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Masquerading
Application Layer Protocol: Web Protocols
Encrypted Channel: Symmetric Cryptography
Proxy
Ingress Tool Transfer
Obfuscated Files or Information
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Malware Protection
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
APT Daxin rootkit targets manufacturing with kernel-mode persistence, requiring enhanced east-west traffic security and zero trust segmentation for software development environments.
Industrial Automation
Taiwan manufacturing firm compromise demonstrates critical vulnerability to advanced persistent threats targeting industrial control systems and operational technology networks.
Computer/Network Security
Daxin resurface alongside Stupig backdoor highlights need for improved threat detection capabilities and multicloud visibility to counter sophisticated China-linked APT operations.
Telecommunications
Advanced rootkit deployment requires enhanced encrypted traffic inspection and egress security controls to prevent lateral movement through telecommunications infrastructure.
Sources
- Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoorhttps://thehackernews.com/2026/07/daxin-resurfaces-in-taiwan-alongside.htmlVerified
- Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoorhttps://www.security.com/threat-intelligence/daxin-returns-stupigVerified
- Daxin: A Chinese-linked malware that is dangerous and nearly impossible to detecthttps://www.techrepublic.com/article/daxin-a-chinese-linked-malware-that-is-dangerous-and-nearly-impossible-to-detect/Verified
- ‘Most advanced’ China-linked backdoor ever, Daxin, raises alarms for cyber-espionage investigatorshttps://cyberscoop.com/daxin-china-linked-symantec-cyber-espionage/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial access may still occur, the attacker's ability to exploit this access would likely be constrained by enforced workload segmentation.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained by identity-based access controls and workload isolation.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement would likely be constrained by east-west traffic controls that limit unauthorized inter-workload communications.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command-and-control communications would likely be constrained by enhanced visibility and control over network traffic.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts would likely be constrained by strict egress policies that monitor and control outbound traffic.
The attacker's ability to maintain a prolonged undetected presence would likely be constrained by continuous monitoring and real-time policy enforcement.
Impact at a Glance
Affected Business Functions
- Manufacturing Operations
- Supply Chain Management
- Intellectual Property Management
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of sensitive intellectual property and manufacturing process data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement regular patch management to address vulnerabilities in software and systems.
- • Deploy zero trust segmentation to limit lateral movement within the network.
- • Enhance east-west traffic security to detect and prevent unauthorized internal communications.
- • Utilize threat detection and anomaly response systems to identify and respond to unusual activities.
- • Establish egress security and policy enforcement to monitor and control outbound data flows.



