Dormant Medium impact Espionage Checked 2w ago

China-linked Daxin spyware resurfaces in Taiwan factory

Security researchers found the China-linked Daxin rootkit running on a compromised network at a Taiwan-based subsidiary of a multinational high-tech manufacturer, discovered in May 2026. A previously unknown backdoor called Stupig was found on the same machine, and clues suggest the intrusion may have gone undetected for years. Investigators believe attackers likely got in through an outdated single sign-on portal running long-expired software.

Started
May 12, 2026
Latest activity
Jul 15, 2026
Attributed to
China-linked espionage groupLikely
Where
Taiwan
Sectors
Manufacturing, Technology
Scale
one Taiwan-based subsidiary of a multinational high-tech manufacturer

Current status

The July 17, 2026 iThome report repeated Symantec's findings and did not confirm more attacker activity, more victims, or a closure.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

Symantec linked Daxin to a China-linked espionage group but did not name it or confirm that the same actor created Stupig.

Impact

Attackers had a kernel-mode backdoor and a novel pre-login SYSTEM-level backdoor on the victim's network, giving them stealthy long-term access; researchers say the intrusion may have gone undetected for as long as 13 years.

What to do

Organizations running old single sign-on or identity portals should check for outdated Java runtimes and unusual kernel driver installs.

Timeline

  1. Aug 29, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  2. Jul 15, 2026

    Symantec publicly disclosed the Daxin and Stupig findings, describing the compromise and likely initial access via an outdated Digiwin single sign-on portal.

    Containedsecurity.com
  3. Jun 1, 2026

    A renamed copy of Stupig (kbdus1.dll) was found in the System32 directory after the first detection prompted the attackers to adjust their tradecraft.

    Containedsecurity.com
  4. May 28, 2026

    The Stupig backdoor (a.dll) was first detected on the host.

    Emergingsecurity.com
  5. May 12, 2026

    The compromised host began reporting telemetry, the earliest point Symantec could confirm activity on the network.

    Emergingsecurity.com

Sources

Related reports