HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Daxin Malware and New “Stupig” Pre‑Login Backdoor Discovered in Taiwan Manufacturing Firm

A Taiwan manufacturing company was found to be infected with the Daxin kernel‑mode rootkit and a novel pre‑login backdoor called Stupig. The incident highlights gaps in SOC 2 access‑control monitoring and the need for continuous, auditable evidence of privileged‑access protection.

LiveThreat™ Intelligence · 📅 July 17, 2026· 📰 thehackernews.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Daxin Malware and New “Stupig” Pre‑Login Backdoor Discovered in Taiwan Manufacturing Firm

What Happened – Researchers uncovered the re‑emergence of the Daxin kernel‑mode rootkit (srt64.sys) inside a Taiwan‑based manufacturing company after a four‑year dormancy. In the same host, a previously unknown pre‑login backdoor, dubbed Stupig, was also found, giving an attacker persistent, low‑level system access before any user credentials are presented.

Why It Matters for Compliance & Audit Readiness

  • The incident is a textbook example of why SOC 2 Access Controls (CC6.1 Logical Access) must be continuously monitored and auditable.
  • Persistent kernel‑mode implants bypass traditional endpoint AV; continuous evidence collection (e.g., immutable logs, privileged‑access monitoring) is required to prove control effectiveness during an audit.
  • Demonstrating a defensible incident‑response trail and remediation workflow satisfies the SOC 2 principle of Security and helps maintain trust with partners and regulators.

Who Is Affected – Manufacturing and industrial‑automation firms, especially those with supply‑chain exposure to East‑Asian threat actors.

Recommended Actions

  • Map the detection of unauthorized kernel drivers to SOC 2 CC6.1 and CC7.1 (System Operations) controls; capture logs as audit evidence.
  • Deploy privileged‑access‑management (PAM) solutions that enforce MFA for any pre‑login access and restrict admin rights to a minimal set of accounts.
  • Integrate continuous endpoint‑telemetry (EDR) with a SOC‑2‑ready evidence‑store to detect anomalous driver loads in real time.
  • Conduct a focused security‑awareness session on supply‑chain and nation‑state threat profiles for engineering and OT staff.

Source: The Hacker News

Technical Notes – Daxin is a stealthy kernel‑mode rootkit that loads a malicious driver (srt64.sys) to hide its presence and exfiltrate data. Stupig is a pre‑login backdoor that opens a listening socket before credential validation, enabling remote code execution without user interaction. No public CVE is associated; the threat actor is linked to a China‑based APT group.

📰 Original Source
https://thehackernews.com/2026/07/daxin-resurfaces-in-taiwan-alongside.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →