Daxin
Aliases: DELIMEAT
- First seen
- 2022-02-26 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Last IoC activity
- 2026-07-15 19:03:11
- Profile updated
- 2026-07-07 14:23:03
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:in country_code:ru country_code:br
Context
Symantec describes this as a malware written as Windows kernel driver, used by China-linked threat actors. The malware has a custom TCP/IP stack and is capable of hijacking connections.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Daxin_Auto (yara-rule)
Reports & references
- Mandiant — Chinese Espionage Tactics (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Daxin (report)
- teamt5.org — Backdoor Of Driver Analysis Daxin (report)
- Broadcom/Symantec — Daxin Backdoor Espionage (report)
- reuters.com — New Chinese Hacking Tool Found Spurring Us Warning Allies 2022 02 28 (report)
- Broadcom/Symantec — Daxin Malware Espionage Analysis (report)
- bleepingcomputer.com — Chinese Cyberspies Target Govts With Their Most Advanced Backdoor (report)
- nzz.ch — China Soll Mit Praezedenzloser Malware Regierungen Ausspioniert Haben Ld.1672292 (report)
- gist.github.com — 839Fbc54E0D76Bb2626329Cd94274Cd6 (report)
- Broadcom/Symantec — Daxin Backdoor Espionage Analysis (report)
- twitter.com — 1498399791276912640 (report)