Advanced malware attributed to China-linked threat actors, specifically the Daxin kernel-mode rootkit and a newly discovered backdoor named Stupig, has resurfaced in a Taiwan-based manufacturing firm. Daxin, known for its longevity and stealth, was found active in 2026 on a system potentially compromised for over a decade. The intrusion highlights the persistent nature of state-sponsored espionage and the effectiveness of kernel-level rootkits in maintaining long-term access.
Stupig introduces a novel persistence technique by masquerading as a keyboard-layout DLL loaded by winlogon.exe, allowing attackers to execute SYSTEM-level commands directly from the Windows logon screen without triggering audit events. Investigators suspect the initial breach occurred through an outdated SSO portal running legacy Java environments. Additionally, recent reports suggest these threat actors are increasingly leveraging generative AI models like Claude and DeepSeek to automate reasoning and bypass security controls during complex intrusions.
Top comments (0)