CyberSecurity

Daxin Rootkit Resurfaces in Taiwan After 4 Years, Now Paired With New Stupig Backdoor

Published

on

Daxin Rootkit Comes Back From the Dead

A nasty piece of malware that most security teams probably thought was history has just popped up again. Daxin — a kernel-mode rootkit tracked as “srt64.sys” — resurfaced inside a Taiwan manufacturing company, and it brought a friend.

That friend is a previously undocumented backdoor called Stupig. Together, they signal that whoever deployed this toolkit hasn’t retired. They’ve just been waiting.

Daxin first came to light in March 2022, when Symantec (now owned by Broadcom) published a detailed write-up. At the time, the evidence pointed to targeted attacks aimed at specific organizations. The malware was linked to a China-based threat actor, though attribution in cyberspace always comes with caveats.

Now, more than four years later, the same rootkit shows up again. That’s a long gap. Most malware families fade away or get replaced by newer tooling. Daxin apparently didn’t get the memo.

What Exactly Is Daxin?

Daxin is not your run-of-the-mill remote access trojan. It operates at the kernel level, which means it runs with the highest privileges on a Windows system. That gives attackers the ability to hide processes, manipulate system calls, and essentially become invisible to standard security software.

Symantec’s original research described it as a sophisticated, modular framework. It wasn’t just a backdoor — it was a full toolkit for stealthy espionage. The fact that it’s resurfaced in a manufacturing environment fits a broader pattern of attackers targeting industrial and critical infrastructure sectors.

Why Taiwan Manufacturing?

Taiwan’s manufacturing sector is a prime target for state-sponsored espionage. The island is home to a dense supply chain for semiconductors, electronics, and precision machinery. A foothold in one firm can potentially ripple through the entire ecosystem.

In this case, the victim was a manufacturing company, though the report doesn’t name it. That’s typical — most victims prefer to stay anonymous and quietly clean up their networks.

Meet Stupig: The New Backdoor on the Block

Alongside the Daxin rootkit, researchers found a previously unknown backdoor they’ve named Stupig. That’s an odd name, but it’s memorable. The backdoor appears to be a companion piece to Daxin, likely used for post-exploitation activities.

While Daxin handles the stealthy kernel-level persistence, Stupig probably serves as a more conventional backdoor — giving attackers remote access, file transfer capabilities, and command execution. The combination is dangerous: one component hides, the other acts.

Researchers haven’t yet published a full technical breakdown of Stupig’s capabilities. But the fact that it’s been deployed alongside a known state-sponsored rootkit suggests it’s not amateur hour.

What This Means for Defenders

If you’re running a security team at a manufacturing firm, this news should hit close to home. The threat actor behind Daxin is patient. Four years between deployments is a long time to wait, but they clearly haven’t moved on.

Here are some practical takeaways:

  • Kernel-level detection matters. If your EDR doesn’t monitor kernel drivers, you’ll miss Daxin entirely.
  • Check for signed but malicious drivers. Daxin uses a driver file (srt64.sys). Legitimate-looking drivers are a common evasion technique.
  • Hunt for dual-component infections. If you find one backdoor, look for others. Attackers often deploy multiple tools.
  • Monitor outbound traffic. Backdoors need to phone home. Unusual C2 connections are often the first sign of trouble.

For more on how attackers hide their tracks, you might want to read about kernel-level malware detection techniques or check out our guide on identifying backdoor indicators of compromise.

The Bigger Picture: State-Sponsored Espionage Isn’t Going Away

The reappearance of Daxin is a reminder that cyber espionage campaigns don’t follow a timeline. Threat actors re-use tools when they work. They don’t care if the malware is “old” — they care if it’s effective.

Symantec’s 2022 report linked Daxin to a China-nexus actor, and nothing in this latest sighting contradicts that assessment. But attribution is always tricky. The tools are what we can see; the operators behind them remain in the shadows.

For now, the key takeaway is simple: Daxin is back, it’s paired with a new backdoor, and it’s targeting manufacturing. If you’re in that sector, treat this as a wake-up call.

Security teams should also review their incident response playbooks for rootkit infections before they need them. Preparation is cheaper than cleanup.

This story is still developing. Researchers will likely publish more technical details about Stupig in the coming weeks. For now, the message is clear — the threat landscape doesn’t stand still, and neither should your defenses.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version