Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
There is strong evidence to suggest the malware, Backdoor.Daxin, which allows the attacker to perform various communications and data-gathering operations on the infected computer, has been used as recently as November 2021 by attackers linked to China.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacker can also start arbitrary processes and interact with them.
In a November 2019 attack against an information technology company, the attackers used a single PsExec session to first attempt to deploy Daxin before then resorting to Trojan.Owprox.
Daxin is capable of communicating by hijacking legitimate TCP/IP connections. In order to do so, it monitors all incoming TCP traffic for certain patterns. Whenever any of these patterns are detected, Daxin disconnects the legitimate recipient and takes over the connection.
The Daxin sample analyzed appears to be packed with a standard VMProtect packer. Many earlier samples feature an additional, outside, packing layer on top of VMProtect.
When ordered to execute a DLL file, Daxin performs injection into one of the pre-existing “svchost.exe” processes.
When ordered to execute a DLL file, Daxin performs injection into one of the pre-existing “svchost.exe” processes.
Daxin is capable of communicating by hijacking legitimate TCP/IP connections. In order to do so, it monitors all incoming TCP traffic for certain patterns. Whenever any of these patterns are detected, Daxin disconnects the legitimate recipient and takes over the connection.
One of these additional communication methods uses HTTP messages to encapsulate backdoor communications... Our client communicated with the backdoor instance running on “Alice-PC” over HTTP to control a set of infected machines.
One of these additional communication methods uses HTTP messages to encapsulate backdoor communications... Daxin then parses HTTP request headers and extracts the request body. The request body is then interpreted using the same logic as already described in the “Communications protocol” section.
Daxin is also capable of relaying its communications across a network of infected computers within the attacked organization. The attackers can select an arbitrary path across infected computers and send a single command that instructs these computers to establish requested connectivity.
This instructs the backdoor to set up remaining connectivity across malicious nodes... node #1 ... node #2 (HEAD) ... node #3 ...
Daxin’s built-in functionality can be augmented by deploying additional components on the infected computer. Daxin provides a dedicated communication mechanism for such components by implementing a device named “\\.\Tcp4”.
In case the value starts with “http://”, the TCP server details are retrieved from the remote web server... the analyzed sample contacts the provided URL and scans the received HTTP response... The decrypted data are interpreted as the TCP server address and port to use.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows kernel-mode driver backdoor/rootkit used in long-term espionage. It hijacks legitimate inbound TCP connections for encrypted C2 instead of creating its own outbound traffic, making detection difficult, and supports multi-hop communications across infected hosts.
A highly sophisticated Windows kernel-driver backdoor used in a long-running China-linked espionage campaign. It hijacks legitimate TCP/IP connections, establishes encrypted channels via custom key exchange, relays communications across multiple infected hosts, supports network tunneling, and enables file operations and process execution while maintaining stealth on hardened networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.