Symantec reported that Daxin, a stealthy malware family it previously described as among the most advanced linked to a China-aligned threat actor, has reappeared after several years of inactivity. The malware was identified running inside a manufacturing company in Taiwan, indicating that the operators have resumed use of the platform in a live intrusion.
The latest activity also involved deployment of a new backdoor, suggesting the threat actor has updated its tooling or tradecraft alongside Daxin’s return. The combination of a historically sophisticated malware framework and newly observed access tooling points to an ongoing espionage-focused campaign targeting organizations in Taiwan.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Symantec documented a previously unknown Windows backdoor named Backdoor.Stupig on the same compromised host as Daxin at a Taiwan-based subsidiary of a multinational high-tech manufacturer. The malware abuses Windows logon by loading into winlogon.exe as a keyboard-layout provider, letting an attacker type a special "stupig"-prefixed username at the sign-in screen to spawn a SYSTEM shell or run commands.
Symantec had previously discovered Daxin and described it as the most advanced malware it had seen from a China-linked actor. The later reporting states the malware resurfaced four years after this initial discovery.
Daxin was found running inside a manufacturing company in Taiwan, marking the malware's reappearance after four years. The intrusion also involved deployment of a novel backdoor, suggesting updated tooling or tradecraft.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
7 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcecyberaccord.com
Open sourcemalware.news
Open sourcesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.