Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»‘DKnife’ Implant Used by Chinese Threat Actor for Adversary-in-the-Middle Attacks
    Cybersecurity

    ‘DKnife’ Implant Used by Chinese Threat Actor for Adversary-in-the-Middle Attacks

    adminBy adminFebruary 6, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Chinese hackers
    Share
    Facebook Twitter LinkedIn Pinterest Email

    For well over half a decade, a China-linked threat actor has been operating a gateway-monitoring and adversary-in-the-middle (AitM) framework to deliver and interact with backdoors, Cisco’s Talos researchers warn.

    Dubbed DKnife, the framework consists of seven Linux-based implants designed for deep packet inspection, traffic manipulation, and malware delivery, and has been active since at least 2019.

    The framework mainly targets Chinese-speaking users, delivering and interacting with backdoors such as ShadowPad and DarkNimbus on desktop, mobile, and IoT devices.

    DarkNimbus, also known as DarkNights, is supplied by the Chinese firm UPSEC, which was previously associated with the Chinese APT TheWizards, the operator of the Spellbinder AitM framework.

    According to Talos, there are overlaps between DKnife and Spellbinder TTPs, and the WizardNet backdoor has been distributed by DKnife, suggesting “a shared development or operational lineage”.

    The same as Spellbinder, DKnife targets Chinese platforms and applications, including mail and messaging services. Its code also references Chinese media websites, Talos says.

    Advertisement. Scroll to continue reading.

    However, the cybersecurity firm points out that its analysis is based on configuration files from a single command-and-control (C&C) server, and that other servers could be used to target different geographies (WizardNet was used in the Philippines, Cambodia, and the UAE as well).

    DKnife was built to monitor and manipulate network traffic and to interact with backdoors running on victims’ systems. It can update the backdoors, hijack DNS traffic, hijack Android application updates and downloads, and exfiltrate user activity to the C&C.

    It can also hijack Windows and other binary downloads, deploy the ShadowPad and DarkNimbus backdoors, intercept and disrupt traffic associated with antivirus and PC-management products, and monitor and report on the user’s network activity.

    Additionally, it can steal credentials for a major Chinese email provider (by hijacking encrypted connections to extract plaintext usernames and passwords) and can serve phishing pages for other services.

    “Based on the language used in the code, configuration files and the ShadowPad malware delivered in the campaign, we assess with high confidence that China-nexus threat actors operate this tool,” Cisco notes.

    Related: Cisco Patches Vulnerability Exploited by Chinese Hackers

    Related: Chinese APT Mustang Panda Caught Using Kernel-Mode Rootkit

    Related: Chinese APT ‘LongNosedGoblin’ Targeting Asian Governments

    Related: Google Sees 5 Chinese Groups Exploiting React2Shell for Malware Delivery

    Actor AdversaryintheMiddle attacks Chinese DKnife Implant threat
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleYouTube 21.06.251 beta APK Download by Google LLC
    Next Article This finished HBO miniseries is still the gold standard for post-apocalyptic sci-fi
    admin
    • Website

    Related Posts

    Internet Age-Gates Are a Growing Global Threat

    June 5, 2026

    Can Chinese memory maker CXMT help relieve the memory shortage?

    June 1, 2026

    Cisco research finds standard AI safety benchmarks miss the real threat

    May 27, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google Analytics adds source grouping and hostname filtering

    June 13, 2026

    Government Order Shuts Down Fable 5 Despite Anthropic’s Objections

    June 13, 2026

    Google expands limited ad serving policy on Search

    June 13, 2026

    Victory! 702 has Expired!

    June 13, 2026
    Categories
    • Blogging (95)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (261)
    • SEO & Digital Marketing (1,468)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (353)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google Analytics adds source grouping and hostname filtering

    June 13, 2026

    Government Order Shuts Down Fable 5 Despite Anthropic’s Objections

    June 13, 2026

    Google expands limited ad serving policy on Search

    June 13, 2026
    Most Popular
    • Google Analytics adds source grouping and hostname filtering
    • Government Order Shuts Down Fable 5 Despite Anthropic’s Objections
    • Google expands limited ad serving policy on Search
    • Victory! 702 has Expired!
    • Google Publishes Tennessee Search “Blacklist” Guidance
    • Microsoft Ads launches Product Explorer for catalog insights
    • How Jeetu Patel made Cisco unrecognizable
    • Why TikTok Is Expanding Its Premium Ads Push and What That Means for You
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.