DKnife Linux toolkit hijacks router traffic to spy, deliver malware
ID: 4ac3cadb-e3b2-5745-a3cb-83abb727b03f
STIX ID: report--4ac3cadb-e3b2-5745-a3cb-83abb727b03f
Feed Name: Bleeping Computer
Threat Score
Cisco Talos identified DKnife, a seven-component ELF toolkit used since 2019 to hijack gateway/router traffic and perform adversary-in-the-middle activities—including deep packet inspection, DNS and update hijacking, credential harvesting, and delivery of ShadowPad and DarkNimbus backdoors—targeting Chinese services and exfiltrating user activity; IoCs were published and C2 servers remained active as of January 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
