/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Symantec details China-linked backdoor Daxin, a Windows kernel driver that can hijack TCP connections to stealthily connect with command-and-control servers

Security researchers have discovered Daxin, a China-linked stealthy backdoor specifically designed for deployment in hardened corporate networks …

BleepingComputer Bill Toulas

Context & Ripple Effects

Daxin extends a recent run of reports about difficult-to-detect backdoors: researchers had already described SysJoker evading virtually all malware scanning engines across major desktop operating systems. Here, the focus narrows to Windows environments that are explicitly hardened, where covert network control is especially consequential.

It also follows reporting on a malicious Netfilter driver signed by Microsoft and observed communicating with Chinese IPs. The common issue is not a shared campaign claim, but the security exposure created when low-level Windows components are used for stealth.

First-order effects

  • Corporate Windows defenders must investigate Daxin as a kernel-resident persistence and command-and-control threat rather than treating it as an ordinary user-space malware alert.
  • Symantec's disclosure gives security teams a named malware family and its TCP-connection-hijacking behavior to prioritize in incident hunting.

Second-order effects

  • Endpoint-security providers and enterprise security teams face added pressure to detect suspicious kernel and network behavior, especially where conventional malware scanning has shown gaps.
  • Microsoft's earlier Netfilter signing incident makes driver trust and validation a more prominent concern for Windows administrators evaluating low-level threats.

Third-order effects

  • If comparable cases continue, enterprise defense will increasingly depend on visibility into privileged Windows components and covert network flows, not only file-based malware detection.
  • The pattern points to a broader contest over trusted system layers: kernel drivers can turn operating-system trust mechanisms into a stealth channel for intrusion operations.

The trend: Stealthy backdoors are moving deeper into trusted Windows layers, raising the value of behavioral detection in hardened enterprise networks.

Discussion

  • @threatintel @threatintel on x
    NEW: This is Daxin, the most advanced Chinese espionage tool we've ever found. Used to spy on governments worldwide. https://symantec-enterprise- blogs.security.com/... https://twitter.com/...
  • @howelloneill Patrick Howell O'Neill on x
    Xi's successful bid to make China a ‘cyber superpower’: The “most advanced piece of malware” ever seen from China, Chinese hackers have exploited more 0day in the last decade than any other country, vulnerability exploitation spiked six times last year. https://www.technologyrevi…
  • @jorge_guajardo Jorge Guajardo on x
    “China's offensive cyber capabilities ‘rival or exceed’ those of the United States, said Winnona DeSombre, a research fellow at the Harvard Belfer Center, in congressional testimony on China's cyber capabilities on February 17.” https://www.technologyreview.com/ ...
  • @_marklech_ Mark Lechtik on x
    The digital signature on some of the samples, signed by Anhua Xinda Technology Co., was in use by the XPath rootkit, tool leveraged by a Chinese-speaking TA against Central Asian targets around 2017 https://twitter.com/...
  • @cisagov @cisagov on x
    A new report from @threatintel gives details about taking down a sophisticated malware. This is great work by @BroadcomSW & shows how the power of partnerships - like the #JCDC - can help raise our collective defense. https://symantec-enterprise- blogs.security.com/...
  • @dyn___ Aaron Grattafiori on x
    There's a number of interesting things in here, hopefully we see some other write ups. Injecting into other app TCP streams is slick, but not sure how that remains stealthy unless the destination server is also compromised? Am I missing something? https://twitter.com/...
  • @cisajen Jen Easterly on x
    Cool success story for the Joint Cyber Defense Collaborative (#JCDC). Our partners @threatintel tapped into the JCDC and worked alongside @CISAgov to engage w/multiple foreign governments to assist in detection & remediation of this sophisticated malware. Learn more about Daxin. …
  • @campuscodi Catalin Cimpanu on x
    Broadcom's Symantec team has published a report today on the Daxin backdoor, which they have described as “the most advanced piece of malware Symantec researchers have seen from China-linked actors” 👀👀👀👀 👀 https://symantec-enterprise- blogs.security.com/... https://twitter.com/..…
  • @kimzetter Kim Zetter on x
    “a high degree of stealth and permits the attackers to communicate with infected computers on highly secured networks, where direct internet connectivity is not available. These features are reminiscent of Regin, an advanced espionage tool discovered...in 2014” and linked to GCHQ…