Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Daxin is a Windows kernel-driver backdoor whose stealthy communications capabilities alarmed cyber-espionage investigators. Symantec described it as the most advanced malware its researchers had seen used by a China-linked actor—a judgment by the company, not an independently established ranking of all malware.
What is the Daxin backdoor?
Daxin is a backdoor delivered as a Windows kernel driver. A backdoor gives an attacker a way to access or control a compromised system; Daxin’s distinguishing feature, as described in Symantec’s February 28, 2022 report, was how it could communicate without behaving like a conventional remote-access service.
Instead of opening its own network service and waiting for an incoming connection, Daxin could monitor incoming TCP traffic for a trigger pattern. When it recognized one, it could disconnect the legitimate recipient and take over the connection. The malware then negotiated an encrypted channel to carry commands and responses.
How could Daxin communicate inside hardened networks?
It could hide its communications in existing traffic
Taking over a connection that was already headed to a legitimate service could help Daxin’s communications blend into ordinary network activity. Symantec assessed that this approach could also work in environments with strict firewall rules, where opening a new service or allowing unusual outbound connections might attract attention.
#1 Best Overall
It could relay traffic through infected computers
Daxin could route communications over attacker-selected paths through other infected machines. Symantec’s March 8, 2022 technical follow-up describes a laboratory demonstration of a multi-hop channel across several infected nodes. This means an operator could use compromised systems as relays rather than relying on a direct connection to each target.
It could reach services inside a compromised network
The malware could tunnel connections to legitimate internal services reachable from an infected computer. CISA’s February 28, 2022 notice said Daxin enabled remote actors to communicate with secured devices that were not directly connected to the internet. Together, these capabilities could give an operator a path into systems that were otherwise difficult to reach from outside the organization.
It also supported system-control functions
Symantec reported that Daxin could read and write files, start processes, and interact with processes. Researchers assessed that its main advantage was not a uniquely broad set of commands, but the stealth and communications methods used to operate within a compromised network.
Why did investigators raise alarms?
A kernel driver operates at a privileged level of Windows, while Daxin’s connection takeover and relay features could make its command-and-control traffic harder to distinguish from legitimate activity. The combination mattered: covert access could be maintained through network paths that ordinary perimeter controls might not expose as a new service.
Rank #3
Symantec’s Threat Hunter team, part of Broadcom Software, called Daxin “without doubt the most advanced piece of malware Symantec researchers have seen used by a China-linked actor.” That wording reflects Symantec’s assessment and the malware it had observed; it should not be read as a measured comparison against every malware family or every threat actor.
Who linked Daxin to China?
Symantec made the China-linked attribution based on technical and operational associations. Its report described Daxin activity alongside Trojan.Owproxy, which Symantec associated with Slug, also called Owlproxy, and identified other overlaps with tools it attributed to Chinese espionage actors.
Rank #4
Those associations support Symantec’s analytic attribution, but they are not a public legal finding identifying a government operator. The evidence described in the report is about links among tools and activity, not a publicly named individual or agency.
What is known about Daxin’s timeline and targets?
Symantec’s February 2022 report said the earliest known Daxin sample dated to 2013 and that the most recent attacks it had identified occurred in November 2021. The report identified victims in government, telecommunications, transportation, and manufacturing.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
These are the public observations reported at the time, not a complete account of every infection. They also do not establish whether Daxin has been active or inactive since 2021. The consulted public accounts do not provide a current prevalence estimate or establish the present validity of the published indicators of compromise.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should an organization do if it finds Daxin indicators?
CISA urged organizations to review Symantec’s original report and its indicators of compromise (IOCs). An IOC can help investigators identify potentially related files or activity, but a match should be treated as a lead for investigation rather than, by itself, a full diagnosis of the intrusion or proof of its scope.
For a suspected kernel-level compromise, escalate to the organization’s incident-response and digital-forensics team and use relevant government reporting channels. CISA said Broadcom/Symantec worked with the agency to engage targeted governments and assist with detection and remediation. The public accounts do not provide a complete response playbook or establish current detection-tool coverage, so a generic cleanup utility or endpoint product should not be assumed to diagnose or remove a targeted rootkit.
When choosing an incident-response resource, relevant capabilities include:
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
- Ability to acquire and analyze volatile and kernel-level evidence.
- Experience investigating targeted intrusions and rootkits.
- Ability to coordinate with the organization’s security operations team.
- Access to relevant government reporting channels.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

