logo

004

ID: 4c26590d-de79-4986-a2fd-d7aad5c410ae

STIX ID: report--4c26590d-de79-4986-a2fd-d7aad5c410ae

Threat Score

85/100

Uploaded: 2026-05-14

Published Date: 2026-05-14

Last Modified Date: 2026-05-14

Created by: Thesis Research

TLP:GREEN
...
...
Cisco Talos researchers uncovered DKnife, a modular Linux-based gateway AitM framework operated by China-nexus actors that uses seven implants to perform deep packet inspection, TLS termination, DNS hijacking, credential harvesting, binary and Android update hijacking, and delivery of ShadowPad and DarkNimbus backdoors. Targeting routers and edge devices, DKnife intercepts and manipulates traffic to harvest credentials (including Chinese email providers), replace legitimate downloads and app updates, exfiltrate data from popular Chinese apps, and relay activity summaries to remote C2, indicating a sophisticated, targeted campaign against Chinese-speaking users and regional targets.