Cybersecurity

How the Daxin backdoor managed to remain undetected for 13 years on a strategic Taiwanese industrial network?

In the invisible world of cyber threats, some attacks manage to stay under the radar for years. This is the case with the spyware Daxin, recently discovered active on the network of a Taiwanese manufacturer, revealing a rare and worrying sophistication in the field of cybersecurity.

Imagine you are the IT security manager of a high-tech company. You think you have everything under control, but an invisible threat has been lurking in your system for over a decade. This is exactly what happened with Daxin, a spyware that defied all security protocols to infiltrate a strategic network. How could this software go unnoticed for so long?

Key takeaways

  • The spyware Daxin was found active on a Taiwanese network, despite a first discovery in 2022.
  • Daxin operates by hijacking legitimate connections to evade network monitoring tools.
  • Another malware, Stupig, was discovered on the same network, opening an administrator access right from the Windows login screen.

Discovery of Daxin and its operation

In 2022, Symantec had already highlighted Daxin, associated with a China-linked actor. This year, researchers found this spyware active on the network of a Taiwanese subsidiary of a multinational high-tech manufacturer. Daxin operates as a driver at the heart of the Windows system, giving it direct access to the machine’s operation.

Its infiltration technique relies on monitoring incoming traffic to hijack legitimate connections, allowing it to transmit its commands without being detected by conventional monitoring tools. The software is capable of relaying its commands between infected machines, even those cut off from the Internet, thus increasing its range of action.

Stupig: a new threat

In addition to Daxin, researchers discovered Stupig, another previously unknown malware. It registers as a keyboard layout provider, a component that Windows automatically loads at startup. This ploy allows Stupig to infiltrate the winlogon.exe process and open an administrator access if an ID starting with “stupig” is entered at the login screen.

This software also installs interception points on Windows authentication functions, allowing it to capture credentials in transit. A reference to an additional file, msyun.dll, was spotted, although this file was never found on the machine.

Attackers’ entry point

The attackers initially penetrated the network via a Digiwin single sign-on portal, using outdated Java installations (JDK 1.5 and 1.6) dating from 2009 to 2011. These versions are no longer supported, thus opening a breach in the system’s security.

The compromised machine emitted no telemetry data before May 2026, making it difficult to assess the exact duration of the spyware’s presence. However, the compilation dates of the tools suggest they may have remained silent for over a decade.

Cybersecurity challenges in 2026

In 2026, cybersecurity continues to face increasingly complex challenges, largely due to the growing ingenuity of threats like Daxin and Stupig. Companies must be extra vigilant and invest in advanced detection technologies to protect themselves effectively.

The revelations about Daxin and Stupig highlight the importance of keeping systems up to date and guarding against security vulnerabilities, particularly those related to outdated software. The case of the Taiwanese subsidiary shows that even the most strategic infrastructures can be vulnerable.

Evolution of cyber threats and defense technologies

As cyber threats evolve, defense technologies must keep pace. Companies like Symantec work tirelessly to develop solutions capable of detecting and neutralizing complex threats. The use of artificial intelligence and machine learning in cybersecurity could be the key to quickly identifying suspicious behavior and isolating threats before they cause damage.

Companies are encouraged to adopt a proactive approach to security, training their employees in best practices and regularly conducting security audits to identify potential vulnerabilities.

FAQ on Daxin and cybersecurity

What is the Daxin software?

Daxin is a sophisticated spyware that operates as a driver at the heart of the Windows system, allowing access and control of a compromised machine by hijacking legitimate connections.

How does Stupig open an administrator access?

Stupig registers as a keyboard layout provider and integrates into the winlogon.exe process. By entering an ID starting with “stupig” at the login screen, it allows commands to be executed with SYSTEM rights.

Why are outdated Java installations dangerous?

Outdated Java installations, like those used by Digiwin, no longer receive security updates, making them easy targets for cyberattacks seeking to exploit known vulnerabilities.

What is the importance of telemetry in cybersecurity?

Telemetry allows the collection of data on network and machine activity, helping to identify and analyze potential threats. Without telemetry, it is difficult to determine when and how an intrusion occurred.

You may also like

Leave a reply

Your email address will not be published. Required fields are marked *