
Daxin Rootkit Resurfaces in Taiwan Alongside New Stupig Backdoor Malware
CyberespionageMalwareThreatIntelligenceCriticalInfrastructure
The advanced kernel-mode rootkit malware Daxin (srt64.sys), previously linked to a China-associated threat actor, has resurfaced after over four years in a Taiwan-based manufacturing firm, alongside a newly identified backdoor named Stupig. Daxin was first documented by Symantec (Broadcom) in March 2022, with evidence indicating its use in targeted attacks. The Stupig backdoor operates as a pre-login SYSTEM-level implant, though further technical specifics remain undisclosed. No CVE IDs or exact attack timelines were provided in the report. The resurgence highlights persistent threats to critical infrastructure in the region.