{"id":210764,"date":"2026-02-06T13:35:00","date_gmt":"2026-02-06T18:35:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/02\/06\/dknife-linux-toolkit-hijacks-router-traffic-to-spy-deliver-malware\/"},"modified":"2026-02-06T15:00:10","modified_gmt":"2026-02-06T20:00:10","slug":"dknife-linux-toolkit-hijacks-router-traffic-to-spy-deliver-malware","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/02\/06\/dknife-linux-toolkit-hijacks-router-traffic-to-spy-deliver-malware\/","title":{"rendered":"DKnife Linux toolkit hijacks router traffic to spy, deliver malware"},"content":{"rendered":"<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/dknife-linux-toolkit-hijacks-router-traffic-to-spy-deliver-malware\/\">DKnife Linux toolkit hijacks router traffic to spy, deliver malware<\/a><\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/dknife-linux-toolkit-hijacks-router-traffic-to-spy-deliver-malware\/\">https:\/\/www.bleepingcomputer.com\/news\/security\/dknife-linux-toolkit-hijacks-router-traffic-to-spy-deliver-malware\/<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-02-06 13:35:00<\/a><\/p>\n<p>Source Domain: <a href=\"www.bleepingcomputer.com\">www.bleepingcomputer.com<\/a><\/p>\n<p style=\"text-align:center\">\n<p>A newly discovered toolkit called DKnife has been used since 2019 to hijack traffic at the edge-device level and deliver malware in espionage campaigns.<\/p>\n<p>The framework serves as a\u00a0post-compromise framework for traffic monitoring and adversary-in-the-middle (AitM) activities. It is designed to intercept and manipulate traffic destined for endpoints (computers, mobile devices, IoTs) on the network.<\/p>\n<p>Researchers at Cisco Talos say that DKnife is an ELF framework with seven Linux-based components designed for deep packet inspection (DPI), traffic manipulation, credential harvesting, and malware delivery.<\/p>\n<p> <img decoding=\"async\" src=\"https:\/\/www.bleepstatic.com\/c\/w\/GitLab-970x250.png\" alt=\"Wiz\" style=\"margin-top: 0px;\"\/><\/p>\n<p>The malware features Simplified Chinese language artifacts in component names and code comments, and explicitly targets Chinese services such as email providers, mobile apps, media domains, and WeChat users.<\/p>\n<p>Talos researchers assess with high confidence that the operator of DKnife is a China-nexus threat actor.<\/p>\n<p><img decoding=\"async\" alt=\"DKnife's seven components and their functionality\" height=\"563\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2026\/February\/seven.jpg\" width=\"900\"\/><strong>DKnife&#8217;s seven components and their functionality<\/strong><br \/>Source: Cisco Talos<\/p>\n<p>Researchers couldn&#8217;t determine how the network equipment is compromised, but found that DKnife\u00a0delivers and interacts with the ShadowPad and DarkNimbus backdoors, both associated with Chinese threat actors.<\/p>\n<p>DKnife consists of seven modules, each responsible for specific activities related to communication with the C2 servers, relaying or altering\u00a0traffic, and hiding the malicious traffic origin:<\/p>\n<ul>\n<li><strong>dknife.bin<\/strong> &#8211; responible for packet inspection and attack logics, it also reports attack status, user activities, and sends collected data<\/li>\n<li><strong>postapi.bin<\/strong> &#8211;\u00a0relay component between DKnife.bin and C2 servers<\/li>\n<li><strong>sslmm.bin<\/strong> &#8211; custom reverse proxy server derived from\u00a0HAProxy<\/li>\n<li><strong>yitiji.bin<\/strong> &#8211; creates a virtual Ethernet interface (TAP) on the router and bridges it into the LAN to route the attacker&#8217;s traffic<\/li>\n<li><strong>remote.bin<\/strong> &#8211;\u00a0peer-to-peer VPN client using the n2n VPN software<\/li>\n<li><strong>mmdown.bin<\/strong> &#8211; malware downloader and updater for Android APK files<\/li>\n<li><strong>dkupdate.bin<\/strong> &#8211;\u00a0DKnife download,&#8230;<\/li>\n<\/ul>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/dknife-linux-toolkit-hijacks-router-traffic-to-spy-deliver-malware\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>DKnife Linux toolkit hijacks router traffic to spy, deliver malware https:\/\/www.bleepingcomputer.com\/news\/security\/dknife-linux-toolkit-hijacks-router-traffic-to-spy-deliver-malware\/ Publish Date: 2026-02-06 13:35:00&#8230;<\/p>\n","protected":false},"author":1,"featured_media":210765,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.bleepstatic.com\/content\/hl-images\/2024\/03\/05\/hand.jpg","fifu_image_alt":"","footnotes":""},"categories":[48],"tags":[71,32,57,34],"class_list":["post-210764","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux","tag-linux","tag-malware","tag-security","tag-threat-actor"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/210764"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=210764"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/210764\/revisions"}],"predecessor-version":[{"id":210766,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/210764\/revisions\/210766"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/210765"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=210764"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=210764"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=210764"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}