At a Glance
| Actor or group | Unnamed China-linked espionage group (per Symantec’s 2022 attribution) |
| Activity type | Suspected long-term cyber espionage |
| Targets | Taiwan-based subsidiary of a multinational high-tech manufacturer |
| Scale | One confirmed host; intrusion possibly undetected for up to 13 years |
| Law-enforcement status | No charges or public enforcement action reported |
| Source | Symantec Threat Hunter Team (Broadcom) |
TL;DR
Symantec found Daxin malware running on a compromised host in Taiwan in May 2026. That is more than four years after the company first exposed the kernel-mode rootkit. Researchers also found a previously unknown backdoor on the same machine, named Backdoor.Stupig.
What Happened
The victim was a Taiwan-based subsidiary of a multinational high-tech manufacturer. Investigators recovered two tools. The first was a signed kernel driver dropped in the system drivers folder, identical to the Daxin sample documented in 2022. The second was Stupig, deployed first as a.dll and later renamed to closely mimic a legitimate Windows keyboard-layout library.
The likely entry point was an outdated single sign-on portal still running Java installations from 2009 to 2011. Both Java versions passed end-of-life years ago. Notably, the host reported no telemetry before 12 May 2026, so the tools may have sat there unseen for a long stretch.

Why Stupig Stands Out
Stupig registers itself as a keyboard-layout provider. Windows then loads it into the logon process at startup. Meanwhile, the DLL returns a valid layout pointer, so keyboards keep working and nothing looks wrong to an administrator. The backdoor watches the logon screen for a specific username prefix. Anything typed after that prefix runs as SYSTEM, before anyone signs in. The system then returns a normal failed-logon response, so no unusual audit event appears. Symantec describes this as “an access method most defenders are not aware of nor watching for.”
Who Is Behind It
Symantec attributed Daxin to a China-linked espionage group back in 2022, and called it “the most advanced piece of malware” it had seen from such an actor. That assessment rested on technical links and on other China-associated tools found on the same machines. No individual has been charged, and no group is publicly named.
The Stupig link is weaker, and the researchers say so plainly. According to the Symantec Threat Hunter Team’s report, no code-level relationship between the two tools has been established. However, both carry compile timestamps a few weeks apart in early 2013. Shared development habits suggest Stupig’s author knew Daxin’s source code. Whether the same operators deployed both remains unconfirmed.
Impact and Scale
Symantec reported one compromised host in this case, not a campaign count. Still, the timeline matters more than the number. The 2013 timestamps, combined with the actor’s habit of quiet long-term persistence, suggest the intrusion may have run for roughly 13 years. As Symantec puts it, the operation “never went away; it went quiet.”
Daxin’s tradecraft explains that longevity. Rather than dialing out to a server, the driver watches inbound TCP traffic and hijacks legitimate connections to carry encrypted commands. It also relays commands across chains of infected machines, reaching systems with no internet access. Consequently, network monitoring rarely catches it. In 2022, Symantec worked with CISA through the Joint Cyber Defense Collaborative to notify affected governments.
What Comes Next
Taiwan’s manufacturing sector remains a focus of reported Chinese intrusion activity. Defenders should hunt for unexpected DLLs registered as keyboard-layout providers, especially names that differ from legitimate files by a single character. Additionally, audit repeated failed logons with odd usernames. Retire end-of-life Java and portal software, since that was the suspected way in here. Finally, treat hosts with no telemetry history as blind spots, not as clean.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.