FortiGuard Labs is aware of a newly discovered backdoor dubbed Daxin. Discovered by Symantec, this backdoor allows an attacker to gather and perform various command and control actions and data exfiltration on victim machines. Because of our partnership with the Cyber Threat Alliance, we were provided with IOCs to create Fortinet protections in advance so that it would be ready for today’s announcement.What separates this backdoor from many others is that Daxin is a Windows kernel level driver, also referred to as rootkits. Kernel level rootkits operate at ring 0, which allows them to operate at
the highest privileges of the operating system with impunity. What makes this threat dangerous and very effective is that it is able to leverage existing services and utilize them to perform whatever is needed without raising any suspicion by network administrators and or endpoint security software. Daxin does not contain any unique capabilities from other backdoors; however, besides its ability to run at kernel level, Daxin can also intercept TCP/IP connections in real time for further evasion. Further communications noted were the use of a custom TCP/IP stack to communicate in multiple nodes on highly secured networks.This backdoor has been attributed to state sponsored threat actors of China where targets are organizations that are of interest to the Chinese government.What Operating Systems Were Targeted?Windows operating systems.What is the Likelihood of Exploitation?Low. This is due to the attacks observed being focused on the specific interests by the threat actors behind Daxin, and not as part of a widespread attack.Is this Limited to Targeted Attacks?Yes, all attacks observed were limited to state sponsored targets. This included governmental organizations of interest, telecommunications, transportation, and manufacturing sectors as well.What is the Status of Coverage?Customers running the latest AV definitions are protected by the following signatures:W32/Agent.FF56!tr.bdrW32/Backdoor.DAXIN!trW32/PossibleThreatW64/Agent.FF56!tr.bdrW64/Backdoor.DAXIN!trW64/Agent.QWHWSZ!trMalicious_Behavior.SBW32/Exforel.B!tr.bdrDx.BG3D!trW64/Agent.WT!trW32/PossibleThreat
More Stories
chromium-120.0.6099.71-1.el9
FEDORA-EPEL-2023-a0fcd69d86 Packages in this update: chromium-120.0.6099.71-1.el9 Update description: Update to 120.0.6099.71 Update to 120.0.6099.62, upstream release fixes follow security issues:...
chromium-120.0.6099.71-1.el7
FEDORA-EPEL-2023-3782f9a3bf Packages in this update: chromium-120.0.6099.71-1.el7 Update description: Update to 120.0.6099.71 Update to 120.0.6099.62, upstream release fixes follow security issues:...
chromium-120.0.6099.71-1.el8
FEDORA-EPEL-2023-d1b0df83e0 Packages in this update: chromium-120.0.6099.71-1.el8 Update description: Update to 120.0.6099.71 Update to 120.0.6099.62, upstream release fixes follow security issues:...
doctl-1.101.0-2.fc40
FEDORA-2023-72ab10f1de Packages in this update: doctl-1.101.0-2.fc40 Update description: Automatic update for doctl-1.101.0-2.fc40. Changelog * Sat Dec 9 2023 Mikel Olasagasti...
seamonkey-2.53.18-1.el7
FEDORA-EPEL-2023-fd36857b5e Packages in this update: seamonkey-2.53.18-1.el7 Update description: Update to 2.53.18 Read More
seamonkey-2.53.18-1.el8
FEDORA-EPEL-2023-76db503610 Packages in this update: seamonkey-2.53.18-1.el8 Update description: Update to 2.53.18 Read More