Daxin

Aliases: DELIMEAT

First seen
2022-02-26 00:00:00
Malware type
backdoor
Family
Malware family
Last IoC activity
2026-07-15 19:03:11
Profile updated
2026-07-07 14:23:03

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:in country_code:ru country_code:br

Context

Symantec describes this as a malware written as Windows kernel driver, used by China-linked threat actors. The malware has a custom TCP/IP stack and is capable of hijacking connections.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Daxin_Auto (yara-rule)

Reports & references

  • Mandiant — Chinese Espionage Tactics (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Daxin (report)
  • teamt5.org — Backdoor Of Driver Analysis Daxin (report)
  • Broadcom/Symantec — Daxin Backdoor Espionage (report)
  • reuters.com — New Chinese Hacking Tool Found Spurring Us Warning Allies 2022 02 28 (report)
  • Broadcom/Symantec — Daxin Malware Espionage Analysis (report)
  • bleepingcomputer.com — Chinese Cyberspies Target Govts With Their Most Advanced Backdoor (report)
  • nzz.ch — China Soll Mit Praezedenzloser Malware Regierungen Ausspioniert Haben Ld.1672292 (report)
  • gist.github.com — 839Fbc54E0D76Bb2626329Cd94274Cd6 (report)
  • Broadcom/Symantec — Daxin Backdoor Espionage Analysis (report)
  • twitter.com — 1498399791276912640 (report)

External references