Daxin
Daxin is a highly sophisticated Windows kernel-mode backdoor and rootkit associated with China-linked espionage activity.
Daxin
Family profile
Daxin is a highly sophisticated Windows kernel-mode backdoor and rootkit associated with China-linked espionage activity. Public reporting places its use as far back as 2013, with operations against governments, critical infrastructure, and later a Taiwanese high-tech manufacturing environment. It is notable for long-term stealth, deep integration with the Windows networking stack, and design choices suited for segmented, heavily defended networks.
Daxin is implemented as a signed kernel driver and masquerades as legitimate system software. It hooks Windows NDIS and TCP/IP structures, registers as a protocol driver, and effectively operates its own malicious TCP/IP functionality alongside the legitimate stack. Rather than relying on obvious outbound beaconing, it monitors inbound TCP traffic for specific trigger patterns, hijacks selected legitimate connections, and establishes encrypted command-and-control channels over those sessions. It can also forge packets, send DNS requests, and tunnel traffic through compromised hosts, enabling multi-hop access to isolated systems without direct internet connectivity.
Its backdoor functionality includes arbitrary file read and write, remote command execution, execution of EXE payloads, DLL execution via injection into user-mode processes, and communication with additional local components. Earlier technical analyses also documented kernel-assisted remote execution using APC-based user-mode shellcode delivery. Daxin has been observed executing commands with SYSTEM privileges and stealing credentials in Taiwanese high-tech manufacturing environments.
Persistence and concealment are central to Daxin’s design. It stores encrypted configuration data in the Windows Registry, uses packing and obfuscation in some samples, and blends malicious traffic into normal network activity. Its architecture supports covert relay operations across chains of infected nodes, making it especially effective for espionage inside hardened enterprise and critical infrastructure networks.
Daxin is widely regarded as one of the most technically advanced malware platforms publicly linked to a China-aligned espionage actor.
Capabilities
- Credential Theft
- Defense Evasion
- Exfiltration
- Persistence
- Post Exploitation
- Process Injection
- Spoofing
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
MITRE ATT&CK
Daxin in ATT&CK
27 distinct techniquesReporting
Research mentioning Daxin
Daxin Malware Resurfaces in Taiwan With Stupig Backdoor
Symantec reported that Daxin, a stealthy malware family it previously described as among the most advanced linked to a China-aligned threat actor, has reappeared after several years of inactivity. The malware was identified running inside a manufacturing company in Taiwan, indicating that the operators have resumed use of the platform in a live intrusion. The latest activity also involved deployment of a new backdoor, suggesting the threat actor has updated its tooling or tradecraft alongside Daxin’s return. The combination of a historically sophisticated malware framework and newly observed access tooling points to an ongoing espionage-focused campaign targeting organizations in Taiwan.