BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Daxin malware resurfaces with Stupig backdoor in Taiwan attack

Dormant rootkit Daxin resurfaces with novel Stupig backdoor after 13 years undetected.

  • The Daxin kernel-mode rootkit, dormant for over four years, has resurfaced on a compromised host at a Taiwan-based manufacturing subsidiary alongside a new backdoor called Stupig.
  • Both malware artifacts carry compilation timestamps from early 2013, suggesting the attack may have gone undetected for 13 years.
  • Stupig uses a novel technique by registering as a keyboard-layout provider, enabling SYSTEM-level command execution from the Windows logon screen before any user signs in.

A sophisticated kernel-mode rootkit known as Daxin, first documented by Symantec in March 2022, has resurfaced after more than four years inside a Taiwan-based subsidiary of a multinational high-tech manufacturer. The same compromised machine also harbored a previously unreported backdoor called Stupig, according to findings from the Symantec and Carbon Black Threat Hunter Team.

- Advertisement -

Both artifacts carry a compilation timestamp from early 2013, although the machine did not begin reporting telemetry until May 12, 2026. “The malware also supported multi-hop communications through chains of infected hosts, allowing operators to reach systems on isolated network segments,” Broadcom noted.

Daxin avoids direct outbound connections by monitoring incoming TCP traffic for specific patterns and hijacking existing legitimate connections for encrypted command-and-control. Stupig achieves persistence by registering as a keyboard-layout provider, causing win32k.sys to load it into winlogon.exe at system startup.

“Stupig uses a technique not documented in any known malware family,” the cybersecurity arm of Broadcom said. A trojanized keyboard-layout DLL lets an attacker run commands as System directly from the Windows logon screen before anyone signs in.

The host may have been compromised through an outdated version of the Digiwin single sign-on portal using end-of-life Java Development Kit installations. The discovery shows the cyber espionage operation never completely stopped but instead maintained stealthy persistence in targeted networks.

- Advertisement -

Meanwhile, Hunt.io observed a suspected China-linked threat actor using Anthropic Claude Code and DeepSeek models to automate intrusions against government and financial systems. “Claude Code serves as the execution engine, managing agentic tool use, bash command execution, session persistence, and task parallelization,” the threat intelligence firm said.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Fed Hikes Rate to 4%, First Since 2023; Bitcoin Flat $75.5K

The Federal Reserve raised its benchmark rate by 25 basis points to a 3.75%-4.00%...

Circle Launches Arc Mainnet Amid Senate Rejection; Stock Dips 6%

Circle launched the Arc mainnet on Wednesday, one day after the CLARITY Act failed...

Russian spies use Telegram, crypto to recruit teens for sabotage

Russian spies are using Telegram and cryptocurrency to recruit teenagers across Europe for acts...

Anchorage Bank Adds Etherlink Custody, Including Uranium Token

Anchorage Digital Bank, the first federally chartered crypto bank in the U.S., has added...

AI Coding Assistant Hijacked to Spread Shai-Hulud Worm in 100 Repos

A hacker hijacked an active AI coding-assistant session at a SaaS firm to deploy...

Must Read

This is How to Buy and Sell Bitcoin

Now more than ever, there are a variety of ways to enter and exit the crypto market. While this is good, the availability of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading