Symantec researchers discovered the China-linked Daxin rootkit and a new Stupig backdoor operating on a compromised Taiwanese manufacturing network, revealing a potential thirteen-year undetected intrusion into critical infrastructure.
Key Points
- The Daxin Windows kernel-mode rootkit, first documented in 2022, remains active and capable of hijacking legitimate network traffic to bypass security monitoring.
- The newly identified Stupig backdoor disguises itself as a keyboard-layout DLL to execute commands with SYSTEM privileges directly from the Windows login screen.
- Both malicious tools feature 2013 compilation timestamps, suggesting the compromised host may have remained under attacker control for over a decade.
- Investigators suspect the initial breach occurred through an outdated Digiwin single sign-on portal running end-of-life Java software from 2009 to 2011.
- Stupig evades detection by avoiding standard authentication logs, allowing attackers to gain high-level system access before a user even logs in.