Netskope Threat Labs

Daxin

ATP Sandbox Adv. HeuristicsAV

Daxin is malware written as a Windows kernel driver that Symantec attributes to China linked threat actors. It implements a custom TCP/IP stack and can hijack connections on compromised systems, and its kernel mode design places it beneath most user mode defenses.

First seen
May 2022
Last seen
October 2026
Alert Name
Trojan.Agent.Daxin.A
Trojan.Agent.Daxin.B
Win32.Backdoor.Daxin
Win32.Trojan.Daxin
Win64.Backdoor.Daxin