{"id":211380,"date":"2026-02-06T09:56:00","date_gmt":"2026-02-06T14:56:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/02\/06\/china-linked-dknife-aitm-framework-targets-routers-for-traffic-hijacking-malware-delivery\/"},"modified":"2026-02-08T16:00:09","modified_gmt":"2026-02-08T21:00:09","slug":"china-linked-dknife-aitm-framework-targets-routers-for-traffic-hijacking-malware-delivery","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/02\/06\/china-linked-dknife-aitm-framework-targets-routers-for-traffic-hijacking-malware-delivery\/","title":{"rendered":"China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/02\/china-linked-dknife-aitm-framework.html\">China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/02\/china-linked-dknife-aitm-framework.html\">https:\/\/thehackernews.com\/2026\/02\/china-linked-dknife-aitm-framework.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-02-06 09:56:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">Feb 06, 2026<\/span><\/span><span class=\"p-tags\">Malware \/ IoT Security<\/span><\/p>\n<p>Cybersecurity researchers have taken the wraps off a gateway-monitoring and adversary-in-the-middle (AitM) framework dubbed <strong>DKnife<\/strong> that&#8217;s operated by China-nexus threat actors since at least 2019.<\/p>\n<p>The framework comprises seven Linux-based implants that are designed to perform deep packet inspection, manipulate traffic, and deliver malware via routers and edge devices. Its primary targets seem to be Chinese-speaking users, an assessment based on the presence of credential harvesting phishing pages for Chinese email services, exfiltration modules for popular Chinese mobile applications like WeChat, and code references to Chinese media domains.<\/p>\n<p>&#8220;DKnife&#8217;s attacks target a wide range of devices, including PCs, mobile devices, and Internet of Things (IoT) devices,&#8221; Cisco Talos researcher Ashley Shen noted in a Thursday report. &#8220;It delivers and interacts with the ShadowPad and DarkNimbus backdoors by hijacking binary downloads and Android application updates.&#8221;<\/p>\n<p>The cybersecurity company said it discovered DKnife as part of its ongoing monitoring of another Chinese threat activity cluster codenamed Earth Minotaur that&#8217;s linked to tools like the MOONSHINE exploit kit and the DarkNimbus (aka DarkNights) backdoor. Interestingly, the backdoor has also been put to use by a third China-aligned advanced persistent threat (APT) group called TheWizards.<\/p>\n<p>An analysis of DKnife&#8217;s infrastructure has uncovered an IP address hosting WizardNet, a Windows implant deployed by TheWizards via an AitM framework referred to as Spellbinder. Details of the toolkit were documented by ESET in April 2025.<\/p>\n<p>The targeting of Chinese-speaking users, Cisco said, hinges on the discovery of configuration files obtained from a single command-and-control (C2) server, raising the possibility that there could be other servers hosting similar configurations for different regional targeting.<\/p>\n<p>This is significant in light of infrastructural connections&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/02\/china-linked-dknife-aitm-framework.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>China-Linked DKnife AitM Framework Targets Routers for Traffic Hijacking, Malware Delivery https:\/\/thehackernews.com\/2026\/02\/china-linked-dknife-aitm-framework.html Publish Date: 2026-02-06&#8230;<\/p>\n","protected":false},"author":1,"featured_media":211381,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjYyMn4uLO-VZgiUrwRtAtJIOgkMnxpxz8eAMF1qozW3TT6F7vTTebQnOZu_ZHcioB-mqEHV7AT35sHZPKp5X2W6kJj0l8fZDPZoS11oLDOMh3v8_6rX_C5IiLlxrlv0eCEPFUZ2Nv6VG4BNcEiDH7yJ0HyJ-5CvN2EL-VsQP85QydfaaLQ62BME9d_-frU\/s1600\/hijacking.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,31,32,25],"class_list":["post-211380","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-exploit","tag-malware","tag-phishing"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/211380"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=211380"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/211380\/revisions"}],"predecessor-version":[{"id":211382,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/211380\/revisions\/211382"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/211381"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=211380"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=211380"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=211380"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}