AUTO-UPDATED

Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network

Symantec researchers discovered the China-linked Daxin rootkit and a new Stupig backdoor operating on a compromised Taiwanese manufacturing network, revealing a potential thirteen-year undetected intrusion into critical infrastructure.

Key Points

  • The Daxin Windows kernel-mode rootkit, first documented in 2022, remains active and capable of hijacking legitimate network traffic to bypass security monitoring.
  • The newly identified Stupig backdoor disguises itself as a keyboard-layout DLL to execute commands with SYSTEM privileges directly from the Windows login screen.
  • Both malicious tools feature 2013 compilation timestamps, suggesting the compromised host may have remained under attacker control for over a decade.
  • Investigators suspect the initial breach occurred through an outdated Digiwin single sign-on portal running end-of-life Java software from 2009 to 2011.
  • Stupig evades detection by avoiding standard authentication logs, allowing attackers to gain high-level system access before a user even logs in.

Why it Matters

This discovery highlights the extreme longevity of sophisticated state-sponsored cyber espionage campaigns that utilize stealthy, kernel-level persistence mechanisms. By targeting overlooked areas like keyboard-layout providers and Windows login processes, these threats demonstrate that traditional network monitoring is often insufficient to detect long-term, deeply embedded intrusions.
Securityaffairs.com Published by Pierluigi Paganini
Read original