A China-linked advanced malware called Daxin has resurfaced at a Taiwan manufacturing firm in 2026, over four years after it was first publicly documented, alongside a newly discovered backdoor called Stupig that hides within the Windows logon process to execute commands with SYSTEM privileges before any user signs in. Both tools carry 2013 compilation timestamps, raising the possibility the intrusion went undetected for up to 13 years. Separately, a suspected China-linked actor has also been observed using AI tools, including Anthropic's Claude Code and DeepSeek, to automate cyberattacks against government and financial targets across multiple countries.