Daxin: Stealthy Backdoor Designed for Attacks Against Hardened Networks

Discussion in 'malware problems & news' started by Rasheed187, Mar 5, 2022.

  1. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Seems to be quite a sophisticated attack on Windows. However, shouldn't Windows get some type of protection method against malicious rootkit drivers? Perhaps some type of hypervisor that runs on top. Actually, certain third party security companies like McAfee/Intel actually tried this back in 2008, but perhaps this stuff should be built-in or even hardware based.

    https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/daxin-backdoor-espionage
     
  2. moredhelfinland

    moredhelfinland Registered Member

    Joined:
    Mar 31, 2009
    Posts:
    417
    Location:
    Finland
    Just wondering...this \\.\Tcp4. Is it related to Windows network settings TCP/IPv4?
    If i disable IPv4 and reconfigure my lan only use IPv6, does this Daxin work?
     
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    No I don't think so, they simply register this device which is named TCP4. Of course, keep in mind that this malware is not geared to home user PC's but it's still a bit shocking to see how creative these hackers are when it comes to trying to evade security tools. What I don't understand is why operating systems like Windows even offer all of these options that are mostly used by malware and not legitimate software.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.