China-Linked DKnife Spyware Hijacking Internet Routers Since 2019
ID: 55f6a605-afab-51a2-b4df-55d95517e9f3
STIX ID: report--55f6a605-afab-51a2-b4df-55d95517e9f3
Feed Name: HackRead
Threat Score
Cisco Talos researchers disclosed DKnife, a China-linked toolkit active since at least 2019 that implants into internet routers and edge devices to perform AitM update hijacks, decrypt and exfiltrate traffic (including WeChat and Signal), drop security updates, and deliver backdoors such as ShadowPad and DarkNimbus; the toolkit includes seven specialized implants and had active command-and-control as of January 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
