Security researchers have found the China-linked Daxin malware still running on a compromised system inside the Taiwan-based subsidiary of a multinational manufacturer. The discovery suggests the intrusion may have remained hidden for years, with indicators pointing back to 2013.
According to the report, Symantec’s Threat Hunter Team identified Daxin on the affected host and also uncovered a newly named backdoor called Stupig. The pairing raises concerns that the attackers maintained persistent access to the company’s network while avoiding detection over a long period.
Daxin is described as a rootkit, a type of malware designed to stay concealed while giving attackers deep access to infected systems. Finding it still active more than a decade after the suspected initial compromise highlights the difficulty of detecting stealthy threats that can quietly operate inside enterprise environments.
The case adds to broader concerns about long-term cyber espionage operations targeting organizations in strategic industries and regions. It also shows how older malware families can remain relevant when attackers continue to adapt their tools and preserve footholds inside corporate networks.