Symantec details China-linked backdoor Daxin, a Windows kernel driver that can hijack TCP connections to stealthily connect with command-and-control servers
Security researchers have discovered Daxin, a China-linked stealthy backdoor specifically designed for deployment in hardened corporate networks …
BleepingComputerBill Toulas
Context & Ripple Effects
Daxin extends a recent run of reports about difficult-to-detect backdoors: researchers had already described SysJoker evading virtually all malware scanning engines across major desktop operating systems. Here, the focus narrows to Windows environments that are explicitly hardened, where covert network control is especially consequential.
It also follows reporting on a malicious Netfilter driver signed by Microsoft and observed communicating with Chinese IPs. The common issue is not a shared campaign claim, but the security exposure created when low-level Windows components are used for stealth.
First-order effects
Corporate Windows defenders must investigate Daxin as a kernel-resident persistence and command-and-control threat rather than treating it as an ordinary user-space malware alert.
Symantec's disclosure gives security teams a named malware family and its TCP-connection-hijacking behavior to prioritize in incident hunting.
Second-order effects
Endpoint-security providers and enterprise security teams face added pressure to detect suspicious kernel and network behavior, especially where conventional malware scanning has shown gaps.
Microsoft's earlier Netfilter signing incident makes driver trust and validation a more prominent concern for Windows administrators evaluating low-level threats.
Third-order effects
If comparable cases continue, enterprise defense will increasingly depend on visibility into privileged Windows components and covert network flows, not only file-based malware detection.
The pattern points to a broader contest over trusted system layers: kernel drivers can turn operating-system trust mechanisms into a stealth channel for intrusion operations.
The trend: Stealthy backdoors are moving deeper into trusted Windows layers, raising the value of behavioral detection in hardened enterprise networks.
NEW: This is Daxin, the most advanced Chinese espionage tool we've ever found. Used to spy on governments worldwide. https://symantec-enterprise- blogs.security.com/... https://twitter.com/...
Xi's successful bid to make China a ‘cyber superpower’: The “most advanced piece of malware” ever seen from China, Chinese hackers have exploited more 0day in the last decade than any other country, vulnerability exploitation spiked six times last year. https://www.technologyrevi…
“China's offensive cyber capabilities ‘rival or exceed’ those of the United States, said Winnona DeSombre, a research fellow at the Harvard Belfer Center, in congressional testimony on China's cyber capabilities on February 17.” https://www.technologyreview.com/ ...
The digital signature on some of the samples, signed by Anhua Xinda Technology Co., was in use by the XPath rootkit, tool leveraged by a Chinese-speaking TA against Central Asian targets around 2017 https://twitter.com/...
A new report from @threatintel gives details about taking down a sophisticated malware. This is great work by @BroadcomSW & shows how the power of partnerships - like the #JCDC - can help raise our collective defense. https://symantec-enterprise- blogs.security.com/...
There's a number of interesting things in here, hopefully we see some other write ups. Injecting into other app TCP streams is slick, but not sure how that remains stealthy unless the destination server is also compromised? Am I missing something? https://twitter.com/...
Cool success story for the Joint Cyber Defense Collaborative (#JCDC). Our partners @threatintel tapped into the JCDC and worked alongside @CISAgov to engage w/multiple foreign governments to assist in detection & remediation of this sophisticated malware. Learn more about Daxin. …
Broadcom's Symantec team has published a report today on the Daxin backdoor, which they have described as “the most advanced piece of malware Symantec researchers have seen from China-linked actors” 👀👀👀👀 👀 https://symantec-enterprise- blogs.security.com/... https://twitter.com/..…
“a high degree of stealth and permits the attackers to communicate with infected computers on highly secured networks, where direct internet connectivity is not available. These features are reminiscent of Regin, an advanced espionage tool discovered...in 2014” and linked to GCHQ…