Daxin Rootkit Resurfaces After 13 Years: China-Linked Kernel Backdoor Found Alongside New Pre-Auth 'Stupig' DLL on Taiwan Manufacturer's Network — Threadlinqs Intelligence
As of 2026-07-18, Daxin Rootkit Resurfaces After 13 Years: China-Linked Kernel Backdoor Found Alongside New Pre-Auth 'Stupig' DLL on Taiwan Manufacturer's Network is a high-severity malware threat attributed to Unattributed China-linked APT (China), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1489 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Unattributed China-linked APT · China · ESPIONAGE
Symantec's Threat Hunter Team found the China-linked Daxin kernel-mode rootkit (first documented in March 2022) still active on the network of a Taiwan-based subsidiary of a multinational high-tech
In May 2026, Symantec's Threat Hunter Team began receiving telemetry from a compromised host belonging to a Taiwan-based subsidiary of a multinational high-tech manufacturer. Investigation revealed the host was running Backdoor.Daxin, a sophisticated Windows kernel-mode rootkit that Symantec first publicly documented in March 2022 and, at the time, assessed as the most advanced malware it had observed from a China-linked actor. The driver component, srt64.sys, is installed under %SystemRoot%\System32\drivers and carries a January 2013 compile timestamp, indicating the implant (or a closely related build) has existed since at least that year — roughly 13 years of potential dwell time.
Daxin's defining characteristic is its command-and-control model: rather than initiating outbound connections that would stand out to network monitoring, the kernel driver passively inspects inbound TCP traffic for a specific trigger pattern, disconnects the legitimate recipient, and hijacks the existing TCP session to carry an encrypted C2 channel after a key exchange. This design lets Daxin operators relay commands through chains of compromised hosts (multi-hop) to reach systems on network segments with no direct internet egress, while generating minimal anomalous outbound traffic of its own.
Alongside Daxin, researchers identified a second, previously unreported implant they named Backdoor.Stupig. Stupig is a DLL (initially deployed as a.dll, later renamed kbdus1.dll) that masquerades as a legitimate Microsoft U.S. keyboard-layout library (kbdus.dll). It registers itself as a keyboard-layout provider so that win32k.sys loads it into winlogon.exe at system startup, and it returns a valid KBDTABLES pointer to avoid breaking keyboard functionality and evade casual inspection. Once resident in winlogon.exe, Stupig monitors the Windows logon screen for usernames beginning with the string "stupig"; any text following that prefix is executed as a SYSTEM-privileged command on the secure desktop before any user has authenticated. Because the interaction never completes a real logon, it produces an ordinary failed-login result rather than a distinguishable authentication event, leaving no meaningful audit trail. Stupig was also found hooking SspiCli!LsaLogonUser and Advapi32!CredUnprotectA inside winlogon.exe, indicating a credential-interception capability layered on top of the pre-auth command execution.
Stupig's DLL carries a February 2013 compile timestamp — one month after Daxin's driver — and researchers found no code-level overlap between the two implants. However, their co-deployment on the same host, complementary functionality (network-level stealth C2 versus pre-auth local execution), and near-identical 2013 build dates strongly suggest coordinated development and operation by the same or closely affiliated China-linked group, rather than coincidental co-infection.
The suspected initial access vector on the Taiwan subsidiary was an outdated Digiwin single sign-on (SSO) portal still running end-of-life Java Development Kit versions 1.5 and 1.6 — software lineage dating to 2009-2011 — consistent with a long-unpatched edge service providing an entry point that was never remediated. Symantec's telemetry timeline shows the host reporting activity from May 12, 2026, with a.dll first detected May 28, 2026, and the renamed kbdus1.dll variant observed June 1, 2026, triggering the investigation that ultimately traced both implants back to 2013-era tooling.
Separately, an unrelated but geographically and thematically adjacent C2 IP, 112.213[.]124.132, was reported sharing an identical HTTP header fingerprint with known TencShell C2 infrastructure — a Go-based implant derived from the open-source Rshell framework and previously documented by Cato CTRL as suspected China-linked tooling used against a global manufacturer. While TencShell is a distinct campaign/toolset from Daxin/Stupig, its overlap in targeting (manufacturing sector, China-linked attri
Target sectors: manufacturing, high tech, government administration, telecoms, transport
Target regions: taiwan, Asia-Pacific
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1587, T1190, T1059, T1106, T1547, T1547, T1543, T1547, T1068, T1014