Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework
ID: 574107f2-8584-586b-9378-b7ee7b0210e8
STIX ID: report--574107f2-8584-586b-9378-b7ee7b0210e8
Feed Name: Cisco Talos
Cisco Talos discovered and analyzed “DKnife,” a sophisticated Linux‑based gateway monitoring and AitM framework composed of seven ELF implants that perform deep packet inspection, DNS and update hijacking, credential harvesting, AV disruption, and delivery of ShadowPad, DarkNimbus and WizardNet backdoors; artifacts and code comments indicate China‑nexus operators, active C2 infrastructure (as of Jan 2026), and targeted Chinese‑language services though the tooling can affect a wide range of devices including routers, PCs, mobile and IoT devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
