Daxin is a highly sophisticated Windows kernel-mode backdoor and rootkit associated with China-linked espionage activity. Public reporting places its use as far back as 2013, with operations against governments, critical infrastructure, and later a Taiwanese high-tech manufacturing environment. It is notable for long-term stealth, deep integration with the Windows networking stack, and design choices suited for segmented, heavily defended networks.
Daxin is implemented as a signed kernel driver and masquerades as legitimate system software. It hooks Windows NDIS and TCP/IP structures, registers as a protocol driver, and effectively operates its own malicious TCP/IP functionality alongside the legitimate stack. Rather than relying on obvious outbound beaconing, it monitors inbound TCP traffic for specific trigger patterns, hijacks selected legitimate connections, and establishes encrypted command-and-control channels over those sessions. It can also forge packets, send DNS requests, and tunnel traffic through compromised hosts, enabling multi-hop access to isolated systems without direct internet connectivity.
Its backdoor functionality includes arbitrary file read and write, remote command execution, execution of EXE payloads, DLL execution via injection into user-mode processes, and communication with additional local components. Earlier technical analyses also documented kernel-assisted remote execution using APC-based user-mode shellcode delivery. Daxin has been observed executing commands with SYSTEM privileges and stealing credentials in Taiwanese high-tech manufacturing environments.
Persistence and concealment are central to Daxin’s design. It stores encrypted configuration data in the Windows Registry, uses packing and obfuscation in some samples, and blends malicious traffic into normal network activity. Its architecture supports covert relay operations across chains of infected nodes, making it especially effective for espionage inside hardened enterprise and critical infrastructure networks.
Daxin is widely regarded as one of the most technically advanced malware platforms publicly linked to a China-aligned espionage actor.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The configuration is implemented as a generic key-value structure that is stored in an encrypted form in the Windows Registry for persistence.
The Daxin sample analyzed appears to be packed with a standard VMProtect packer. Many earlier samples feature an additional, outside, packing layer on top of VMProtect.
When ordered to execute a DLL file, Daxin performs injection into one of the pre-existing “svchost.exe” processes.
這裡有一份 Ring3 的 Shellcode 會填入 WinExec API 的進入點,還有寫入要執行的指令,之後利用 APC 注入,執行 Shellcode 。
Command and Control Traffic Signaling T1205 Daxin monitors inbound TCP for specific trigger patterns instead of establishing outbound connections.
原先以為此後門 Port knocking 會收特殊的封包格式,結果只是判斷封包內容... 會先判斷封包開頭是否為 DWORD = 0x9910
One of these additional communication methods uses HTTP messages to encapsulate backdoor communications... Daxin then parses HTTP request headers and extracts the request body. The request body is then interpreted using the same logic as already described in the “Communications protocol” section.
Finally, a special message can be used to set up new connectivity across multiple malicious nodes, where the list of nodes is included in a single command.
Daxin utilizes a stealthy command-and-control method by hijacking legitimate network connections, making it difficult to detect with conventional monitoring.
This instructs the backdoor to set up remaining connectivity across malicious nodes... node #1 ... node #2 (HEAD) ... node #3 ...
...eine Schadsoftware eingesetzt, die ihre Kommunikation besonders gut verschleiert hat.
Daxin provides a dedicated communication mechanism for any additional components deployed by the attacker on the affected computer.
Command and Control Traffic Signaling T1205 Daxin monitors inbound TCP for specific trigger patterns instead of establishing outbound connections.
In case the value starts with “http://”, the TCP server details are retrieved from the remote web server... the analyzed sample contacts the provided URL and scans the received HTTP response... The decrypted data are interpreted as the TCP server address and port to use.
There are also dedicated messages that encapsulate raw network packets to be transmitted via a local network adapter. Any response packets are then captured by the malicious driver and forwarded to the remote attacker. This allows the remote attacker to establish communications with any servers reachable from the affected machine on the target’s network, creating a network tunnel for the remote attacker to interact with servers of interest.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used to execute commands with SYSTEM privileges and steal credentials in Taiwanese high-tech manufacturing environments.
Windows kernel-mode rootkit implemented as a signed driver. It does not beacon outbound; instead it waits for specific inbound TCP trigger patterns, hijacks legitimate existing TCP connections for encrypted command-and-control, and can multi-hop through compromised hosts to reach isolated systems.
A signed kernel-mode rootkit/backdoor used in long-term cyber espionage. It monitors inbound TCP traffic, hijacks legitimate connections to carry encrypted commands, and can relay commands across chains of infected machines, including systems without internet access.
A Windows kernel-mode rootkit/backdoor designed for stealthy long-term persistence and covert command-and-control. It monitors incoming TCP traffic for specific patterns, hijacks legitimate existing connections, and can communicate across highly secured or segmented networks without creating obvious outbound C2 traffic.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.