Daxin is a China-linked espionage operation centered on a highly stealthy Windows kernel-mode backdoor of the same name. The activity has been associated with long-running intrusions against entities of strategic interest to China and is notable for deep persistence, covert command execution, and credential theft. Public reporting has linked Daxin to espionage campaigns targeting government, telecommunications, transportation, and manufacturing organizations, including Taiwanese high-technology manufacturing environments. Daxin is distinguished by an unusual command-and-control design that hijacks legitimate inbound TCP traffic rather than relying on conventional outbound beaconing, helping it evade network detection. It also supports multi-hop communications through chains of compromised hosts, enabling access into segmented or otherwise isolated parts of victim networks. In more recent activity, Daxin was found alongside a separate backdoor known as Stupig on a compromised host in Taiwan, suggesting coordinated use by the same or a closely related China-linked espionage actor. Stupig complements Daxin with a novel persistence and execution mechanism. It registers as a keyboard-layout provider so it is loaded by the Windows logon process at startup, allowing command execution with SYSTEM privileges directly from the logon screen before user authentication. It also installed hooks to intercept credential-related functions, supporting credential theft within the victim environment. The co-deployment of Daxin and Stupig, their similar development-era timestamps, and their complementary operational roles indicate a mature, stealth-focused intrusion set designed for long-term access and post-compromise control. The operation reflects a broader Chinese espionage pattern of targeting organizations with strategic or economic value, particularly advanced manufacturing in Taiwan. Available evidence supports assessment of Daxin as a state-linked cyber-espionage capability rather than a financially motivated or ransomware actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operating inside Taiwanese high-tech manufacturing environments with SYSTEM-level command execution and credential theft.
A China-linked espionage actor associated with the Daxin operation, maintaining long-term stealthy persistence in targeted networks and using advanced backdoor capabilities. In 2026, activity was observed on a compromised host in Taiwan, with possible linkage to the newly identified Stupig backdoor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.