China-linked Threat Actors Unleash the Stealthy Daxin Backdoor

A Backdoor in a Ruby Password Checking Library

Chinese threat actors appear to be using a new payload, which is a successor of the Daxin malware family that first surfaced in 2013. Of course, ten-year old malware would not fare well against modern antivirus tools and measures, and this is why the criminals behind it have introduced some major changes. The new threat, dubbed Stealthy Daxin, comes with a wide range of improvements, which could turn it into one of the most dangerous pieces of malware to come out of China.

The Stealthy Daxin operates like a Trojan Backdoor, and it heavily emphasizes on remaining undetected. To achieve this, its creators have used a wide range of tricks. For example, the malware has the ability to hijack running Windows services in order to execute its tasks, or to mask network traffic. The latter is achieved by mixing the malicious network packages with the legitimate ones that the system sends out and receives.

Another peculiar feature of the Stealthy Daxin Backdoor is its ability to execute code on multiple machines at once. The criminals can send one command to an infected network, and all active systems will execute it. This allows for swift and destructive actions, and it also means that the Stealthy Daxin operators are not going for low-hanging fruit. Instead. They are determined on compromising entire networks and spreading laterally.

To top it all off, Stealthy Daxin has the ability to execute remote commands, and work with the file system. These two features alone allow the implant to deploy additional malware, steal files, and much more.

March 1, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.