Description
Daxin is malware written as a Windows kernel driver that Symantec attributes to China linked threat actors. It implements a custom TCP/IP stack and can hijack connections on compromised systems, and its kernel mode design places it beneath most user mode defenses.
Stats
- First seen
- May 2022
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| Trojan.Agent.Daxin.A |
| Trojan.Agent.Daxin.B |
| Win32.Backdoor.Daxin |
| Win32.Trojan.Daxin |
| Win64.Backdoor.Daxin |