Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor
Symantec, Wednesday, July 15th, 2026
Symantec found the China-linked Daxin rootkit active again in Taiwan alongside a previously unknown backdoor called Stupig.
Symantec's Threat Hunter Team observed the reactivation of Backdoor.Daxin, the China-linked kernel-mode rootkit first exposed in 2022, on a Taiwan-based manufacturing subsidiary in May 2026, together with a previously undocumented backdoor named Backdoor.Stupig.
Both tools carry compile timestamps from early 2013, raising the possibility of an intrusion that went undetected for more than a decade.
Daxin avoids outbound traffic entirely, monitoring incoming TCP traffic for patterns and hijacking legitimate connections, making detection far harder. Stupig registers as a keyboard-layout provider to persist in the Windows logon process, running commands as SYSTEM before anyone signs in.
Likely initial access was an outdated Digiwin SSO portal on obsolete JDK builds.