A long-dormant threat actor, Daxin, has re-emerged in Taiwan with a sophisticated pre-login backdoor, dubbed Stupig. This development is particularly concerning, given the increasing reliance on artificial intelligence (AI) for identifying and exploiting software vulnerabilities.
Daxin’s reappearance highlights the ongoing cat-and-mouse game between hackers and cybersecurity professionals. The group, known for its targeted attacks in the past, has now incorporated AI-driven tools to scan for vulnerabilities and inject malicious code into affected systems. This pre-login backdoor allows attackers to maintain persistence on a compromised device, even after the initial intrusion has been mitigated.
The Taiwan-based threat actor’s modus operandi involves using AI-powered scanners to identify software vulnerabilities that can be exploited remotely. Once a vulnerability is discovered, Daxin injects the Stupig backdoor into the affected system, granting remote access and allowing for further exploitation. This approach enables the attackers to evade traditional security measures, such as firewalls and intrusion detection systems.
The use of AI-driven tools in cybersecurity has created new challenges for defenders. While AI can be a powerful tool for identifying vulnerabilities, it also poses a risk if not properly managed. In this case, Daxin’s reliance on AI highlights the need for organizations to prioritize vulnerability management and regular software updates. Failure to do so can leave systems exposed to targeted attacks.
The resurgence of Daxin serves as a reminder that cybersecurity threats are constantly evolving. As AI becomes increasingly integral to both offense and defense, it is essential for organizations to stay ahead of the curve by investing in robust vulnerability scanning tools and implementing strict patch management policies. By doing so, they can minimize the risk of falling victim to targeted attacks.
To mitigate the risk posed by Daxin’s activities, we recommend that organizations prioritize regular software updates, implement a robust vulnerability management strategy, and invest in AI-powered security tools that can detect and respond to emerging threats.
Source: The Hacker News — 2026-07-16