logo

China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery

ID: 45974faf-daf9-5451-a3e1-212f48dd6e7d

STIX ID: report--45974faf-daf9-5451-a3e1-212f48dd6e7d

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-02-06

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cisco Talos disclosed DKnife, an advanced Linux-based gateway-monitoring and adversary‑in‑the‑middle (AitM) framework active since at least 2019 that runs on routers and edge devices to perform deep packet inspection, TLS termination, DNS hijacking, credential harvesting, and the hijacking of binary and Android app updates to deliver backdoors (notably ShadowPad and DarkNimbus); the toolkit is modular (seven components), targets Chinese-speaking users and services, and is linked to other China‑aligned clusters such as Earth Minotaur and TheWizards, presenting a high-risk supply-chain and infrastructure threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.