Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network

2026-07-18T14:51:52Z5637da95521699fd772fd5b7fd24aa7c9b1a66183e095398df1c30fd888bd8d2
ai-assisted-malwarechina-linkedcisadaxinespionageeyfortinetiot-botnetknown-exploited-vulnerabilitiesmicrosoft-sharepointnichireirootkitrussian-campaignscattered-spiderstarland-ratstupigtf1-attackthird-party-breachtuxbot-v3vulnerability-disclosurezoom

What happened

Recent security activity includes multiple high-impact incidents: Symantec discovered the China-linked Daxin Windows kernel rootkit and a new 'Stupig' backdoor running on a Taiwanese manufacturer's network, indicating a stealthy intrusion possibly active since 2013. CISA expanded its Known Exploited Vulnerabilities (KEV) catalog to include multiple vendor flaws (Fortinet FortiSandbox, Microsoft SharePoint, KNX, Oracle and others). Ernst & Young disclosed a data breach tied to a compromised third-party IT support ticketing system. A cyberattack disrupted operations at Japanese food giant Nichre

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
5637da95521699fd772fd5b7fd24aa7c9b1a66183e095398df1c30fd888bd8d2
Enrichment time
2026-07-18T14:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.