China-linked Daxin spyware resurfaces in Taiwan factory
Security researchers found the China-linked Daxin rootkit running on a compromised network at a Taiwan-based subsidiary of a multinational high-tech manufacturer, discovered in May 2026. A previously unknown backdoor called Stupig was found on the same machine, and clues suggest the intrusion may have gone undetected for years. Investigators believe attackers likely got in through an outdated single sign-on portal running long-expired software.
- Started
- May 12, 2026
- Latest activity
- Jul 15, 2026
- Attributed to
- China-linked espionage groupLikely
- Where
- Taiwan
- Sectors
- Manufacturing, Technology
- Scale
- one Taiwan-based subsidiary of a multinational high-tech manufacturer
Current status
The July 17, 2026 iThome report repeated Symantec's findings and did not confirm more attacker activity, more victims, or a closure.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
Symantec linked Daxin to a China-linked espionage group but did not name it or confirm that the same actor created Stupig.
Impact
Attackers had a kernel-mode backdoor and a novel pre-login SYSTEM-level backdoor on the victim's network, giving them stealthy long-term access; researchers say the intrusion may have gone undetected for as long as 13 years.
What to do
Organizations running old single sign-on or identity portals should check for outdated Java runtimes and unusual kernel driver installs.
Timeline
-
Aug 29, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Jul 15, 2026
Symantec publicly disclosed the Daxin and Stupig findings, describing the compromise and likely initial access via an outdated Digiwin single sign-on portal.
Containedsecurity.com -
Jun 1, 2026
A renamed copy of Stupig (kbdus1.dll) was found in the System32 directory after the first detection prompted the attackers to adjust their tradecraft.
Containedsecurity.com -
May 28, 2026
-
May 12, 2026
The compromised host began reporting telemetry, the earliest point Symantec could confirm activity on the network.
Emergingsecurity.com
Sources
- Daxin Returns: Stealthy Malware Resurfaces in Taiwan Alongside a New Backdoor Security.com (Symantec) Jul 15, 2026
- Taiwan factory hit by China-linked malware and backdoor TheHackerNews Jul 16, 2026
- China-linked Daxin spyware targets Taiwan tech firm GBHackers Jul 16, 2026
- Daxin malware attacks Taiwan manufacturers SC World Jul 16, 2026
- Daxin Malware Resurfaces in Taiwan Alongside New Stupig Backdoor SecurityOnline Jul 22, 2026
- 高階後門Daxin、Stupig鎖定臺灣製造業發動攻擊 iThome Jul 17, 2026
Related reports
- Daxin Malware Resurfaces in Taiwan Alongside New Stupig Backdoor Jul 22, 2026
- China-linked Daxin spyware targets Taiwan tech firm Jul 16, 2026
- Daxin malware attacks Taiwan manufacturers Jul 16, 2026
- Taiwan factory hit by China-linked malware and backdoor Jul 16, 2026