Daxin Rootkit Still Active on Taiwan Subsidiary of Global High‑Tech Manufacturer
What Happened — Symantec’s Threat Hunter team discovered the China‑linked Daxin kernel‑mode rootkit, together with a previously unknown “Stupig” backdoor, running on a Taiwanese subsidiary’s Windows host in 2026. The artifacts date back to 2013, indicating a possible 13‑year undetected presence.
Why It Matters for Compliance & Audit Readiness
- Persistent, stealthy malware demonstrates a control gap in continuous monitoring and endpoint integrity verification – a core SOC 2 CC6 (System Operations) requirement.
- The rootkit’s ability to hide C2 traffic underscores the need for documented evidence of network‑traffic analysis and log‑retention controls (SOC 2 CC5 – Monitoring).
- Mapping this long‑standing intrusion to your control framework provides audit‑ready evidence that you actively detect, investigate, and remediate anomalous activity.
Who Is Affected — High‑tech hardware manufacturers, OEMs, and any organization operating legacy Windows infrastructure in regulated or critical‑infrastructure sectors.
Recommended Actions
- Align endpoint‑security controls with SOC 2 CC6: implement continuous kernel‑integrity monitoring and signed‑driver enforcement.
- Augment network‑traffic inspection with baselining and anomaly detection to surface hidden C2 patterns.
- Document the detection, investigation, and remediation steps in your evidence repository for audit readiness.
Source: Security Affairs
Technical Notes — Daxin is a Windows kernel‑mode driver that hijacks existing inbound TCP sessions to embed encrypted C2 traffic, avoiding outbound connections. The newly observed Stupig backdoor shares the same 2013 compilation timestamps. No specific CVE is cited; the threat relies on stealthy kernel manipulation rather than a disclosed software flaw.