Daxin Rootkit and Stupig Backdoor Discovered in Taiwan
🔗 https://cybersecurefox.com/en/daxin-rootkit-stupig-backdoor-taiwan-incident
#daxin #rootkit #stupig #backdoor #windows #keyboard #layout #winlogon.exe #taiwan #cyber #espionage
#rootkit
4 posts · Last used Jul 20
A friendly reminder: Don't be afraid of #Linux #rootkits.
I have just released version 0.3.0 of rk-expose, a modern self-contained #rootkit detection tool that uses several techniques to detect signs of process hiding, file hiding, file content tampering from kernel or user space and can be used for hunting in large, diverse environments. rk-expose is written in #Rust.
Notable changes include:
Clearer output formatGeneric improvements to process hiding detection to avoid false positivesImprovements to cgroupfs process hiding detectionsA Velociraptor artifactAn "auto" subcommand that runs checks using sensible defaults and interprets results
Revisiting Stuxnet: Research Notes
Technical Analysis and Design Insights into the “hide files” mindset
https://malwareanalysisspace.blogspot.com/2026/06/revisiting-stuxnet-research-notes.html?m=1
#Stuxnet #Rootkit #HideFiles
Erst vor zwei Tagen #Manuskript installiert, war darin bereits ein Übeltäter versteckt. Das #bash-Skript legte dies offen. Eine erste Überprüfung lies nicht erkennen, dass die eigentliche #Backdoor schon nachgeladen wurde und aktiv ist. Ich wollte nun mit #ClamAV sicher gehen, doch die Installation ist mir viel zu kompliziert. Daran scheitere ich kläglich.
Schon Schade auf Sicherheit zu verzichten, weil deren Nutzung maximal erschwert wird.
#Arch #Linux #ArchLinux #AUR #Rootkithttps://discourse.ifin.network/t/400-aur-packages-compromised-with-infostealer-and-rootkit/577
You've seen all posts