Daxin (srt64.sys) is a kernel-mode rootkit first documented by Symantec in March 2022, used in targeted attacks since 2013. It monitors incoming TCP traffic for specific patterns and hijacks existing legitimate connections for encrypted C2 communications, making it difficult to detect. It supports multi-hop communications through chains of infected hosts, allowing operators to reach systems on isolated network segments.