The record
Written from the 1 report below. Nothing here is unsourced.
- Symantec and Carbon Black researchers found the Daxin malware, first documented in 2022 and linked to a China-aligned actor, running on a compromised host at a Taiwan-based subsidiary of a multinational high-tech manufacturer in 2026, alongside a previously unreported backdoor named Stupig.
- Stupig masquerades as a Windows keyboard-layout DLL and lets attackers run commands with System privileges from the Windows logon screen before anyone signs in.
- Both tools carry compilation timestamps from early 2013, and researchers suspect the intrusion may have gone undetected for as long as 13 years, possibly entering through an outdated Digiwin single sign-on portal running end-of-life Java versions.
- The finding indicates this espionage operation never fully stopped but stayed hidden in targeted networks using stealth techniques that evade conventional monitoring.
What to watch next
- Whether investigators confirm how and when the Taiwan host was compromised, including the suspected outdated Digiwin SSO portal as the entry point
- Whether further infected hosts or additional malware tied to the same 2013-era toolset are uncovered
- Details on the reported use of Claude Code and DeepSeek models by a suspected China-linked actor to automate intrusions in Taiwan and other countries
Coverage1
1 report
English national1
All filed from India
Named Taiwan · China · Afghanistan · Thailand · United States · Daxin · Digiwin · Microsoft · Stupig · TencShell · Anthropic · Broadcom · Carbon Black Threat Hunter Team
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
