Security researchers have discovered a hidden backdoor linked to China, known as Daxin, which is designed to deploy on corporate networks that have advanced threat detection capabilities.

See also: SockDetour malware used as a Windows backdoor
According to a report published by Symantec 's Threat Hunter team , Daxin is one of the most advanced backdoors ever developed by Chinese hackers .
Daxin takes a different form. It contains a Windows kernel driver program, an atypical choice in the malware landscape. Its stealthiness comes from its advanced communication features, which combine data exchange with regular Internet traffic.
Backdoors provide threat actors with remote access to a compromised computer system, allowing them to steal data, execute commands, or download and install further malware.
Because these tools are typically used to steal information from protected networks or to further compromise a device, they must include some form of data encryption to avoid raising alarms in network traffic monitoring tools.
See also: Bvp47 Linux backdoor went undetected for 10 years
Daxin does this by monitoring network traffic on a device for specific patterns. Once these patterns are detected, it will hijack a legitimate TCP connection and use it to communicate with the command and control server.

By compromising TCP communications, the Daxin malware can hide malicious communication in what is considered legitimate traffic and therefore remain undetectable.
This essentially opens an encrypted communication channel for transmitting or stealing data, all done through a seemingly innocuous TCP tunnel.
Daxin also stands out for its ability to create complex communication paths across multiple infected computers simultaneously using a single command. This allows threat actors to quickly reestablish connections and encrypted communication channels across well-guarded networks.
Symantec threat analysts found evidence linking Daxin to the Chinese state-backed hacking group Slug (also known as Owlproxy)
See also: Group linked to Memento ransomware uses new PowerShell backdoor
According to information, this backdoor has been actively used in attacks since at least November 2019, while researchers detected signs of its development again in May 2020 and July 2020.
The most recent attacks were observed in November 2021, targeting telecommunications, transportation, and construction companies.
