A China-linked threat actor is responsible for deploying Daxin and Stupig malware in targeted attacks against governments, critical infrastructure, and manufacturing firms. The actor uses advanced techniques including kernel-mode rootkits, pre-logon backdoors, and AI-assisted intrusion methods.