004
ID: 4c26590d-de79-4986-a2fd-d7aad5c410ae
STIX ID: report--4c26590d-de79-4986-a2fd-d7aad5c410ae
Threat Score
85/100
Uploaded: 2026-05-14
Published Date: 2026-05-14
Last Modified Date: 2026-05-14
Created by: Thesis Research
TLP:GREEN
...
...
Cisco Talos researchers uncovered DKnife, a modular Linux-based gateway AitM framework operated by China-nexus actors that uses seven implants to perform deep packet inspection, TLS termination, DNS hijacking, credential harvesting, binary and Android update hijacking, and delivery of ShadowPad and DarkNimbus backdoors. Targeting routers and edge devices, DKnife intercepts and manipulates traffic to harvest credentials (including Chinese email providers), replace legitimate downloads and app updates, exfiltrate data from popular Chinese apps, and relay activity summaries to remote C2, indicating a sophisticated, targeted campaign against Chinese-speaking users and regional targets.
