DKnife toolkit abuses routers to spy and deliver malware since 2019
ID: 9325d6d7-7584-53a2-8c7e-91c6c573eaa2
STIX ID: report--9325d6d7-7584-53a2-8c7e-91c6c573eaa2
Feed Name: Security Affairs
DKnife is a multi-component Linux-based adversary-in-the-middle (AitM) toolkit identified by Cisco Talos that compromises routers and edge devices to perform deep-packet inspection, hijack DNS and software/update downloads, terminate TLS, and deliver backdoors (ShadowPad, DarkNimbus). Used since at least 2019 and active in January 2026, the framework targets primarily Chinese-speaking users, intercepts credentials and app/OS updates, disrupts security tools, and demonstrates high technical sophistication and operational persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
