Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor

A

Admin User

Administrator of InfoSecCenter. Passionate about cybersecurity, information security, and technology.

Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM Backdoor
Save

The cybersecurity landscape is a constant game of cat and mouse, yet some threats linger in the shadows far longer than anticipated. In a concerning development for the industrial sector, researchers have identified the resurgence of a sophisticated kernel-mode rootkit known as Daxin within the network of a manufacturing entity in Taiwan. This discovery is not merely a repeat of past campaigns but represents an evolution in offensive capabilities, as the malware was observed operating in tandem with a previously undocumented backdoor named Stupig.

Daxin, which operates under the kernel driver alias srt64.sys, has a history deeply rooted in espionage. Initially attributed to a China-linked advanced persistent threat (APT) group by security researchers at Broadcom’s Symantec division in early 2022, the malware had seemingly gone quiet until now. Its reappearance signals that the threat actors behind it have maintained access to high-value targets or have recently re-initiated campaigns targeting critical infrastructure and supply chains. What sets this recent discovery apart is the deployment of Stupig, a novel pre-login SYSTEM backdoor. This component allows malicious actors to establish persistence and execute commands before a user even authenticates to the machine, providing a stealthy vantage point that is notoriously difficult to detect using standard security protocols.

The implications of this discovery for enterprise security teams are profound. The manufacturing sector, particularly in geopolitical hotspots like Taiwan, remains a prime target for intellectual property theft and espionage. The combination of a kernel-mode rootkit and a pre-login backdoor creates a formidable barrier to defense. Once Daxin embeds itself at the kernel level, it gains the highest possible privileges on a system, effectively allowing it to bypass standard security controls and hide its presence from endpoint detection and response (EDR) systems. The addition of Stupig suggests an intent to maintain long-term, unobtrusive access, enabling threat actors to exfiltrate sensitive data or move laterally through a network without triggering traditional authentication alarms.

Share

Shares: 6
LinkedIn (1) WhatsApp (1) Pinterest (1) Print

You might also like

Comments (0)

Leave a Comment

No comments yet. Be the first to comment!