HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Daxin Rootkit Still Active on Taiwan Subsidiary of Global High‑Tech Manufacturer

Symantec discovered the China‑linked Daxin kernel‑mode rootkit and a new Stupig backdoor on a Taiwanese high‑tech manufacturer’s network, suggesting a 13‑year undetected presence. The finding highlights control gaps that SOC 2 continuous‑compliance programs are designed to detect and document.

LiveThreat™ Intelligence · 📅 July 19, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
securityaffairs.com

Daxin Rootkit Still Active on Taiwan Subsidiary of Global High‑Tech Manufacturer

What Happened — Symantec’s Threat Hunter team discovered the China‑linked Daxin kernel‑mode rootkit, together with a previously unknown “Stupig” backdoor, running on a Taiwanese subsidiary’s Windows host in 2026. The artifacts date back to 2013, indicating a possible 13‑year undetected presence.

Why It Matters for Compliance & Audit Readiness

  • Persistent, stealthy malware demonstrates a control gap in continuous monitoring and endpoint integrity verification – a core SOC 2 CC6 (System Operations) requirement.
  • The rootkit’s ability to hide C2 traffic underscores the need for documented evidence of network‑traffic analysis and log‑retention controls (SOC 2 CC5 – Monitoring).
  • Mapping this long‑standing intrusion to your control framework provides audit‑ready evidence that you actively detect, investigate, and remediate anomalous activity.

Who Is Affected — High‑tech hardware manufacturers, OEMs, and any organization operating legacy Windows infrastructure in regulated or critical‑infrastructure sectors.

Recommended Actions

  • Align endpoint‑security controls with SOC 2 CC6: implement continuous kernel‑integrity monitoring and signed‑driver enforcement.
  • Augment network‑traffic inspection with baselining and anomaly detection to surface hidden C2 patterns.
  • Document the detection, investigation, and remediation steps in your evidence repository for audit readiness.

Source: Security Affairs

Technical Notes — Daxin is a Windows kernel‑mode driver that hijacks existing inbound TCP sessions to embed encrypted C2 traffic, avoiding outbound connections. The newly observed Stupig backdoor shares the same 2013 compilation timestamps. No specific CVE is cited; the threat relies on stealthy kernel manipulation rather than a disclosed software flaw.

📰 Original Source
https://securityaffairs.com/195577/malware/daxin-13-year-old-china-linked-malware-found-still-active-on-manufacturers-network.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →