Symantec's Threat Hunter Team has uncovered a deeply entrenched cyber-espionage operation at a Taiwan-based subsidiary of a multinational high-tech manufacturer, finding both a 13-year-old rootkit and a previously undocumented backdoor operating within the company's network.
The discovery, disclosed on 18 July, centers on Daxin — a Windows kernel-mode rootkit first documented by Symantec — operating alongside a newer implant dubbed Stupig. The findings suggest the attackers have maintained persistent, stealthy access to the manufacturer's infrastructure since as far back as 2013, according to Security Affairs.
A Rootkit That Has Outlasted Entire Security Product Lifecycles
Daxin is no ordinary piece of malware. As a kernel-mode rootkit, it embeds itself at the deepest level of the Windows operating system, granting attackers near-total visibility and control over compromised machines. Rootkits operating at this level can intercept system calls, conceal network traffic, and suppress evidence of their own presence from security software running in user mode.
The 13-year gap between the initial compromise and this year's discovery underscores a sobering reality for defenders: sophisticated state-sponsored threats do not necessarily operate on short timescales. The malware persisted through what may have been multiple rounds of security tool upgrades, operating system patches, and personnel changes at the targeted organisation.
Symantec first documented Daxin years ago, yet the rootkit continues to appear in fresh investigations — suggesting that either eradication efforts at previously compromised sites were incomplete, or that the tool is part of a broader campaign still being actively deployed.
Stupig: A Sign of Ongoing Operations
The co-presence of Stupig alongside the legacy Daxin rootkit is perhaps the most alarming aspect of the finding. Security researchers have long warned against assuming that a long-dormant infection is a resolved one. The discovery of a new, custom-built backdoor on the same network indicates the threat actors have been actively developing their toolkit and maintaining operational capability throughout the decade-long intrusion.
This pattern — combining proven legacy implants with fresh tooling — aligns with tactics observed in campaigns attributed to Chinese-nation-state threat actors. Rather than abandoning old footholds, these groups often build upon them, using established access as a launchpad for new reconnaissance, lateral movement, and data collection objectives.
Taiwan's Tech Sector in the Crosshairs
The choice of target is consistent with a well-documented pattern of cyber-espionage directed at Taiwan's technology manufacturing ecosystem. Taiwanese firms occupy critical positions in global semiconductor and electronics supply chains, making them high-value targets for intelligence collection aimed at both economic advantage and strategic positioning.
The compromise of a subsidiary within a multinational corporation also illustrates how attackers leverage supply-chain relationships. A smaller entity with potentially less mature security posture can serve as a stepping stone into the networks of larger parent organisations, or simply as a means of accessing proprietary manufacturing data and intellectual property.
What This Means for Network Defenders
The Daxin-Stupig finding reinforces several uncomfortable truths for cybersecurity teams across the region and beyond.
First, signature-based detection is insufficient against threats of this sophistication. Kernel-level rootkits are specifically engineered to evade conventional scanning tools. Detecting them requires behavioural analysis — monitoring for anomalous system activity, unexpected kernel-mode drivers, and irregular network patterns that deviate from established baselines.
Second, the assumption that a network is clean must be treated as exactly that — an assumption, not a fact. Organisations handling sensitive technology or operating in geopolitically sensitive sectors should invest in continuous system integrity verification, including regular kernel-level audits and memory forensics.
Third, the multi-year dwell time demonstrated here means that the full scope of data potentially exfiltrated may never be fully quantified. For manufacturers holding proprietary designs, process data, or trade secrets, this uncertainty carries significant strategic and commercial risk.
As regional governments continue to elevate cybersecurity mandates and cross-border threat intelligence sharing, incidents like this serve as concrete evidence that the threat landscape demands vigilance measured not in days or months, but in years.
賽門鐵克威脅狩獵團隊揭露一宗深植於跨國高科技製造商台灣子公司的網絡間諜活動,發現該企業網絡中同時運作著一套長達13年的根套件及一個此前未被記錄的後門程式。
這項於7月18日披露的發現,核心涉及賽門鐵克最早記錄的Windows核心模式根套件「Daxin」,以及代號為「Stupig」的新型植入程式。據Security Affairs報道,調查結果顯示攻擊者自2013年以來便持續且隱蔽地滲透該製造商的基礎設施。
歷經多個安全產品週期仍存在的根套件
Daxin並非普通惡意軟件。作為核心模式根套件,它嵌入Windows作業系統的最底層,賦予攻擊者近乎完全的視野及對受感染機器的控制權。此類根套件能攔截系統調用、隱匿網絡流量,並在運行於用戶模式的安全軟件面前抹除自身存在的證據。
從最初入侵到今年發現之間長達13年的時間差距,為防禦者敲響警鐘:複雜的國家級威脅未必遵循短期運作週期。該惡意軟件歷經可能多輪安全工具升級、作業系統修補程式更新及目標組織人事變動而依然存活。
賽門鐵克多年前已首次記錄Daxin,但該根套件至今仍出現在最新調查中——這暗示先前受感染地點的清除工作可能未徹底,或此工具仍是某個持續活躍部署的更大規模攻擊行動的一部分。
Stupig:持續活躍的行動跡象
與老舊Daxin根套件同時出現的Stupig後門,或許是此次發現最令人擔憂的部分。網絡安全研究人員長期警告,切勿假設長時間潛伏的感染已被解決。在同一網絡中發現全新的定制後門,表明威脅行為者在長達十年的入侵期間持續開發其工具包並維持作戰能力。
這種結合經典老舊植入程式與新型工具的模式,符合歸因於中國國家級威脅行為者的攻擊策略特徵。這些組織並非放棄舊據點,而是往往在此基礎上建立攻防體系,利用已獲取的訪問權限作為跳板,執行新的偵察、橫向移動及數據收集任務。
台灣科技產業成為攻擊目標
此次攻擊目標的選擇,符合長期針對台灣科技製造生態系統的網絡間諜活動模式。台灣企業在全球半導體及電子供應鏈中佔據關鍵地位,使其成為旨在獲取經濟優勢與戰略佈局的情報收集高價值目標。
針對跨國企業子公司發動的入侵亦揭示攻擊者如何利用供應鏈關係。安全防護可能較不成熟的小型實體,可作為進入大型母公司網絡的跳板,或單純作為獲取專有製造數據及知識產權的途徑。
對網絡防禦者的啟示
Daxin與Stupig的並存發現,為該區域及全球網絡安全團隊揭示幾個不容迴避的現狀:
首先,針對此類複雜威脅,基於特徵碼的檢測手段已不夠充分。核心級根套件專門設計用以規避傳統掃描工具,偵測此類威脅需依賴行為分析——監控異常系統活動、非預期的核心模式驅動程式,以及偏離既定基線的非常規網絡模式。
其次,假設網絡環境已淨化的觀點必須被視為純粹假設而非事實。處理敏感技術或處於地緣政治敏感領域的組織,應投入持續的系統完整性驗證,包括定期的核心級審計與記憶體取證。
第三,此次事件展示的多年潛伏期意味著,可能已被竊取的數據全貌或許永遠無法完全量化。對持有專有設計、製造流程數據或商業機密的製造商而言,這種不確定性帶來重大戰略與商業風險。
隨著區域政府持續提升網絡安全規範及跨境威脅情報共享力度,此類事件具體證明:威脅環境所需的警惕程度,必須以年為單位來衡量,而非以日月計。
