Backdoor.Stupig — Windows Login-Screen Keyboard-Layout Provider Backdoor Grants SYSTEM Access, Deployed Alongside Resurfaced Daxin — Threadlinqs Intelligence
As of 2026-07-16, Backdoor.Stupig — Windows Login-Screen Keyboard-Layout Provider Backdoor Grants SYSTEM Access, Deployed Alongside Resurfaced Daxin is a high-severity malware threat attributed to China-linked threat actor (Daxin (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1400 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: China-linked threat actor (Daxin · China · ESPIONAGE
Symantec's Threat Hunter Team discovered Backdoor.Stupig, a novel Windows implant that registers as a malicious keyboard-layout provider DLL loaded into winlogon.exe at startup; typing a username
In May 2026, Symantec's Threat Hunter Team identified telemetry from a previously unknown backdoor — Backdoor.Stupig — running on a compromised host belonging to a Taiwan-based subsidiary of a multinational high-tech manufacturer. Stupig masquerades as a legitimate Windows keyboard-layout component. By registering itself through the OS's keyboard-layout provider extensibility mechanism, Windows loads the malicious DLL into winlogon.exe at system startup, before any user authenticates. The DLL passes through normal keyboard data to avoid detection while silently monitoring the logon screen's username field. If an operator types a username beginning with the prefix "stupig," the malware launches a SYSTEM-privileged command prompt directly on the secure Winlogon desktop; any text following the prefix is executed as a command. Because this occurs entirely pre-authentication, it produces no logon event and bypasses conventional audit trails. Stupig additionally installs inline hooks on SspiCli!LsaLogonUser and Advapi32!CredUnprotectA to intercept credentials processed during legitimate logon attempts.
Investigators recovered two deployment names for the Stupig DLL on the victim host: it first appeared as a.dll on 2026-05-28 and was renamed to kbdus1.dll — closely mimicking the legitimate Windows keyboard-layout library kbdus.dll — on 2026-06-01. A third file, msyun.dll, was referenced in host artifacts but its payload could not be recovered.
The same host also carried Backdoor.Daxin, a signed Windows kernel-mode driver (deployed as srt64.sys in %SystemRoot%\System32\drivers) first documented by Symantec in 2022 but built on techniques dating to at least 2009 (predecessor malware Backdoor.Zala). Daxin operates as a SYSTEM-level rootkit that monitors all inbound TCP traffic for specific trigger patterns; upon match, it disconnects the legitimate recipient, hijacks the connection, and performs a custom encrypted key exchange to establish covert command-and-control. This lets Daxin operators relay a single command across a chain of infected hosts — each node's IP, TCP port, and key-exchange material supplied in one message — enabling operation deep inside air-gapped or heavily firewalled networks without generating anomalous outbound connections. Historically, Daxin activity has used masquerading driver names such as ipfltdrvs.sys, ndislan.sys, and sqlwriter.sys, and has targeted government, telecommunications, transportation, and manufacturing organizations of strategic interest to China.
Both the recovered Daxin driver (srt64.sys, compiled January 2013) and the Stupig DLL (compiled February 2013) carry compile timestamps only weeks apart, and Symantec noted shared development-practice similarities suggesting Stupig's author had access to or familiarity with Daxin's source code, though no direct code-level linkage between the two families was confirmed. The victim host did not begin producing telemetry until 2026-05-12, meaning the intrusion set — attributed to a China-linked threat actor — may have persisted undetected on the network for approximately 13 years. Symantec assesses initial access to the environment likely involved an outdated Digiwin single sign-on portal still running end-of-life Java Development Kit builds (JDK 1.5/1.6, released 2009-2011), though no specific CVE has been attributed to this initial-access path since the exploited weakness stems from unsupported/unpatched legacy software rather than a discrete disclosed vulnerability.
Weaknesses (CWE)
CWE-1188, CWE-306, CWE-284
Target sectors: technology, manufacturing, government administration, telecoms, transport
Target regions: taiwan, Asia-Pacific
Detections & IOCs
As of 2026-08-15, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1190, T1078, T1059, T1547, T1505, T1547, T1548, T1014, T1036, T1556