Skip to content

Daxin Rootkit and Stupig Backdoor Discovered in Taiwanese Manufacturing Facility

The bottom line: The Chinese-attributed Daxin rootkit (srt64.sys) has resurfaced in Taiwan and is now being deployed alongside a new pre-login backdoor called Stupig.

The kernel-mode Daxin rootkit has become active again in a Taiwanese manufacturing company after more than four years of dormancy. Along with it, a previously unknown backdoor named Stupig was discovered that accesses the pre-login system.

The kernel-mode Daxin rootkit was originally documented by Symantec in March 2022. The malware is attributed to a Chinese threat actor and was used in targeted attacks. After a dormant period of more than four years, the rootkit has now been discovered again in a manufacturing facility in Taiwan.

Notably, it is accompanied by the Stupig backdoor, which was previously undocumented. This new component has access to the pre-login phase of the operating system, providing attackers with an early access point before authentication. Such pre-login backdoors are particularly critical because they can bypass standard security mechanisms.

For CISOs, the resurgence of Daxin represents an elevated risk in the supply chain threat landscape, particularly for Taiwanese manufacturing and technology companies. The combination of an established rootkit and a new pre-login backdoor indicates an evolution in attack capabilities. Systems should be monitored for indicators of compromise, especially srt64.sys-related artifacts and unusual pre-login activities.


Source: thehackernews.com · Published 16 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: