Daxin Returns: China-Linked Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Backdoor
Daxin Returns (TL-2026-1362), also tracked as Daxin Returns, is a critical-severity malware campaign, first published 2026-07-15 and last reviewed 2026-09-08. It is attributed to Stupig operators (China) with high confidence, affects Digiwin Single Sign-On Portal, maps to 27 MITRE ATT&CK techniques (T1003, T1005, T1014), and is covered by 9 detection rules and 35 indicators of compromise.
Key facts for TL-2026-1362
- Threat ID
- TL-2026-1362
- Also known as
- Daxin Returns, Backdoor.Daxin, Backdoor.Stupig
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-15
- Last reviewed
- 2026-09-08
- Attribution
- Stupig operators
- Attribution confidence
- HIGH
- Nation-state nexus
- China
- Motivation
- ESPIONAGE
- Target sectors
- manufacturing, high tech, government administration, telecoms, transport
- Target regions
- taiwan, East Asia
- Detection rules
- 9
- Indicators of compromise
- 35
- Updates
- 2026-09-08 · revalidated 1× · latest source
Malware and tooling in Daxin Returns
Malware and tooling: Daxin, Stupig, VMProtect
Symantec's Threat Hunter Team discovered the kernel-mode Daxin rootkit (Backdoor.Daxin, srt64.sys) co-deployed with a previously unknown backdoor, Stupig (a.dll/kbdus1.dll), on a Taiwan-based subsidiary of a multinational high-tech manufacturer. Both samples carry early-2013 compile timestamps, indicating up to 13 years of undetected dwell time; likely initial access was an outdated Digiwin single sign-on portal running end-of-life JDK 1.5/1.6.
How Daxin Returns works
In May 2026, host telemetry at a Taiwan-based subsidiary of a multinational high-tech manufacturer revealed the presence of the kernel-mode rootkit Backdoor.Daxin, first publicly documented by Symantec/Broadcom and jointly detailed by CISA and the FBI in March 2022 as one of the most sophisticated pieces of China-linked espionage tooling ever analyzed. Daxin ships as a Windows kernel driver (observed here as srt64.sys, dropped to %SystemRoot%\System32\drivers) that hooks the Windows NDIS layer, registering a fake NDIS protocol identified internally as "NDISXRPT." Rather than beaconing outbound, Daxin passively monitors legitimate inbound TCP traffic for hardcoded trigger patterns (an HTTP POST containing the string "756981520337", or raw byte sequences 0x10 0x99 0x10 / 0x10 0x99 0x11), hijacks the matched connection by spoofing a TCP RST to the original destination and an ACK to the original source, and then performs a custom bidirectional key exchange to open an encrypted C2 channel over the stolen connection. The driver forges its own IPv4/TCP/UDP packets, bypassing the native Windows TCP/IP stack entirely, and exposes a virtual \\.\Tcp4 device for registering additional service handlers. This design lets operators relay a single command across a chain of previously compromised nodes (each entry specifying IP, port, and key-exchange credentials) to reach systems with no direct internet connectivity — a capability CISA highlighted as enabling access to "secured devices not connected directly to the internet." Daxin can read/write arbitrary files, spawn EXE payloads with redirected stdin/stdout for interactive shell access, and inject DLL payloads into svchost.exe.
Alongside Daxin, the Threat Hunter Team identified a second, previously undocumented implant, Backdoor.Stupig, first seen as a.dll and later renamed kbdus1.dll. Stupig persists by registering itself as a Windows keyboard-layout provider, causing win32k.sys to load it into winlogon.exe at every system startup via an undocumented registry loading path — functionally similar to Winlogon Helper DLL persistence (T1547.004) but not using the documented registry values associated with that technique. The DLL returns a valid KBDTABLES structure to preserve normal keyboard functionality while it silently monitors the logon screen for any username beginning with the string "stupig"; text following that trigger is executed as SYSTEM on the secure desktop (Winsta0\Winlogon) before authentication completes, generating no audit anomaly beyond a routine failed-logon event for an unusual username. Stupig additionally installs inline API hooks on SspiCli!LsaLogonUser and Advapi32!CredUnprotectA — implemented via VirtualProtect, ZwAllocateVirtualMemory, and memcpy to patch the functions in memory — to intercept credentials during the logon and credential-unprotection flows. A LoadLibraryA("msyun.dll") call inside the sample references a companion payload that was not recovered from the compromised host, indicating additional undiscovered tooling.
Investigators assess likely initial access through an outdated Digiwin single sign-on portal exposed by the victim, running Java Development Kit versions 1.5 and 1.6 (installed 2009-2011), both of which reached end-of-life years before the intrusion (JDK 1.5 in 2009, JDK 1.6 in 2013) and were never patched or replaced. No specific CVE has been published for the exploited weakness; the exposure is attributed to prolonged use of unsupported, unpatched middleware rather than a single disclosed vulnerability.
Symantec attributes both tools to the same China-linked espionage actor based on compile timestamps only weeks apart (January and February 2013), consistent low-level development practices, co-deployment on the same host, and complementary operational roles (Daxin for network-level C2 and lateral relay, Stupig for local credential theft and pre-auth code execution), though no direct code-level relationship between the two families was established. The actor has a documented history of long-running espionage operations against governments, telecommunications, transportation, and manufacturing organizations of strategic interest to China, with prior confirmed Daxin activity as recently as November 2021 against two other organizations. The 13-year gap between the 2013 compile timestamps and 2026 detection is consistent with this actor's pattern of extremely long-term, low-noise persistence inside hardened, high-value targets.
MITRE ATT&CK techniques used in TL-2026-1362
Credential Access
T1003 OS Credential Dumping; T1056 Input Capture; T1556 Modify Authentication Process
Collection
Defense Evasion
T1014 Rootkit; T1036 Masquerading; T1055 Process Injection; T1205 Traffic Signaling; T1562 Impair Defenses
Lateral Movement
T1021 Remote Services; T1570 Lateral Tool Transfer
Exfiltration
T1041 Exfiltration Over C2 Channel
Privilege Escalation
T1055 Process Injection; T1547 Boot or Logon Autostart Execution
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1569 Service Execution
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer; T1205 Traffic Signaling; T1572 Protocol Tunneling; T1573 Encrypted Channel
Discovery
T1082 System Information Discovery
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application
Persistence
T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
defense-impairment
Resource Development
Affected products and versions in Daxin Returns
- Digiwin — Single Sign-On Portal
Vulnerable versions: running JDK 1.5; running JDK 1.6
Fixed in: not disclosed - vendor upgrade / JDK replacement recommended - Oracle/Sun — Java Development Kit (JDK)
Vulnerable versions: 1.5; 1.6
Fixed in: any currently supported JDK release - Microsoft — Windows (kernel driver / NDIS subsystem)
Vulnerable versions: builds up to and including 17763 (Windows Server 2019 / Windows 10 v1809) confirmed compatible with analyzed Daxin sample
Fixed in: no vendor patch - detection/EDR based mitigation
Remediation for Daxin Returns
Patches
- Upgrade Digiwin SSO portal to a currently supported release
- Upgrade JDK 1.5/1.6 to a maintained, patched Java runtime
Immediate actions
- Isolate and forensically image any host where srt64.sys, a.dll, or kbdus1.dll are present before remediation
- Hunt for the fake NDIS protocol identifier NDISXRPT and unexpected drivers under %SystemRoot%\System32\drivers
- Hunt for logon attempts with usernames beginning with the string 'stupig' on domain controllers and workstations
- Inspect inbound TCP traffic for the byte patterns 0x10 0x99 0x10 / 0x10 0x99 0x11 or HTTP POST bodies containing '756981520337'
- Rotate credentials for any account that authenticated on a host suspected of Stupig compromise, given the LsaLogonUser/CredUnprotectA hooks
- Decommission or fully patch and network-isolate the Digiwin single sign-on portal and its JDK runtime
Workarounds
- Restrict inbound access to the Digiwin SSO portal to trusted network ranges until upgraded
- Disable or tightly monitor keyboard-layout provider registration paths via application control / WDAC
Longer-term hardening
- Deploy EDR with kernel-driver load monitoring and unsigned/anomalously-signed driver alerting
- Implement network segmentation to limit multi-hop lateral relay paths between hardened and internet-facing segments
- Establish an inventory and forced end-of-life replacement process for internet-facing middleware (SSO portals, JDK runtimes)
- Deploy inline-hook / API-patching detection (integrity monitoring on ntdll.dll, sspicli.dll, advapi32.dll in critical processes)
- Extend log retention and conduct retrospective hunts given demonstrated multi-year dwell capability of this actor
Weaknesses (CWE) in Daxin Returns
CWE-1104, CWE-937, CWE-306
Timeline of Daxin Returns
- JDK 1.5 reaches end-of-life; the Digiwin SSO portal exploited in this campaign was later found running this version, installed as early as 2009.
- Backdoor.Daxin driver srt64.sys carries a compile timestamp in January 2013 (approximate), the earliest evidence of the tool's development.
- JDK 1.6 reaches end-of-life; also found running on the exploited Digiwin SSO portal.
- Backdoor.Stupig DLL (a.dll) carries a compile timestamp in February 2013 (approximate), weeks after the Daxin sample, supporting shared-actor attribution.
- Previously unreported attack: the actor used PsExec to deploy Backdoor.Daxin against an IT company, falling back to Trojan.Owprox (Owlproxy) when driver deployment failed.
- Previously unreported attack: Backdoor.Daxin and Trojan.Owprox both found on a single compromised host at a technology company.
- Previously unreported attack: two failed Daxin driver deployments against a military target; the actor fell back to Trojan.Emulov.
- Daxin previously confirmed deployed against two other organizations, per Symantec's original March 2022 analysis (approximate date within November 2021).
- Symantec/Broadcom publishes the original in-depth Daxin analysis; CISA and the FBI jointly release an advisory on the Daxin backdoor attributed to the People's Republic of China.
- Host telemetry at the Taiwan-based manufacturing subsidiary begins showing anomalous activity later attributed to Daxin and Stupig.
- Stupig sample first detected on the compromised host as a.dll.
- Stupig observed renamed to kbdus1.dll on the compromised host, consistent with keyboard-layout-provider persistence staging.
- Symantec's Threat Hunter Team publishes 'Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor,' detailing the 2026 intrusion and the new Stupig backdoor.
- Security Affairs and other outlets publish follow-on coverage of the Daxin/Stupig campaign, noting the potential 13-year undetected dwell time.
Update history for TL-2026-1362
- 2026-09-08 — Daxin Returns: China-Linked Espionage Group Deploys Backdoor.Daxin and Backdoor.Stupig Against Taiwanese Manufacturer: What changed Attribution confidence MEDIUM → HIGH given newly disclosed predecessor malware (Backdoor.Zala/Exforel, operational since at least 2009) and three previously unreported historical Daxin deployments (2019 IT company, 2020 tech co
Sources cited for Daxin Returns
- Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor
- Daxin Backdoor: In-Depth Analysis, Part One
- CISA and FBI Release Advisory on Daxin Backdoor Used by People's Republic of China
- China-linked Daxin Malware Targeted Multiple Governments in Espionage Attacks
- China-Linked APT Actors Deploying Stealthy Daxin Malware
- 'Most advanced' China-linked backdoor ever, Daxin, raises alarms for cyber-espionage investigators
- Daxin Espionage Backdoor Ups the Ante on Chinese Malware
Threats related to Daxin Returns
- Daxin Rootkit Resurfaces After 13 Years: China-Linked Kernel Backdoor Found Alongside New Pre-Auth 'Stupig' DLL on Taiwan Manufacturer's Network
- Backdoor.Stupig — Windows Login-Screen Keyboard-Layout Provider Backdoor Grants SYSTEM Access, Deployed Alongside Resurfaced Daxin
- Daxin Kernel Rootkit Resurfaces in Taiwan Alongside New Stupig Pre-Auth SYSTEM Backdoor
- FishMonger (I-SOON / Winnti) Ports SprySOCKS Backdoor to Windows — WIN_DRV (RawWNPF Kernel Rootkit) & WIN_PLUS Variants
Detection coverage for TL-2026-1362
As of 2026-09-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1362 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.