Daxin and Stupig: Hidden Attack in Taiwan

Colleagues, I’d like to draw your attention to a cybersecurity update.
Daxin has again been detected in Taiwan — malware linked to a long-running espionage campaign. A new backdoor, Stupig, was identified alongside it.
Both samples carry compilation timestamps from early 2013, suggesting the operation may have remained undetected for a very long time.
Stupig runs before logon: it disguises itself as a keyboard layout component and launches via winlogon.exe with SYSTEM privileges.
Daxin hides its communications by intercepting TCP connections and operates through compromised nodes.
Why it matters: such tools bypass traditional network controls and can persist in infrastructure for years.
Where should organizations place greater emphasis today: EDR, network analytics, or legacy service control?
#cybersecurity #malware #APT #WindowsSecurity

