Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
China-Linked Hackers Target Linux Devices with Malware

China-Linked Hackers Target Linux Devices with Malware

Posted on February 6, 2026 By CWS

A newly identified cyber threat, known as the “DKnife” framework, has emerged as a significant risk to network security. This sophisticated toolset, attributed to China-linked hackers, specifically targets Linux-based routers and edge devices.

Emergence of DKnife and Its Threats

DKnife enables attackers to compromise critical network gateways, giving them a persistent presence within the targeted infrastructure. This allows for precise data monitoring and manipulation, presenting a formidable challenge to network integrity.

Operating as a comprehensive Adversary-in-the-Middle (AitM) framework, DKnife inspects network packets in real-time. Although active since at least 2019, it remained largely undetected until recently. The framework’s components work in unison to hijack legitimate user requests, such as software updates, replacing them with malicious content.

Technical Analysis and Capabilities

Researchers at Cisco Talos discovered the DKnife malware during their investigation into the distribution of the DarkNimbus backdoor. Their findings revealed that DKnife is not merely a passive monitoring tool but a potent attack platform.

The malware intercepts traffic destined for specific services, particularly those popular among Chinese-speaking users, injecting harmful payloads. This tactic underscores the shift of threat actors towards edge devices to circumvent traditional security measures.

Implications and Impact of DKnife

Once a router is compromised by DKnife, all devices connected to it become vulnerable. The malware can selectively disrupt traffic from antivirus products, preventing updates or server communications, and can also harvest sensitive data, such as credentials and device identifiers.

Central to DKnife’s offensive strategy is its capability to hijack binary downloads seamlessly. Utilizing a deep packet inspection (DPI) engine, it monitors network traffic for specific requests, such as Android updates or Windows executables, intervening before these requests reach legitimate servers.

The malware’s process involves intercepting initial update requests, checking them against a local configuration, and sending forged responses to redirect downloads to malicious URLs. This stealthy operation, managed by a component named yitiji.bin, ensures that victims unknowingly install backdoors like ShadowPad or DarkNimbus, granting attackers full control over endpoint devices.

To stay informed on the latest cybersecurity threats, follow us on Google News, LinkedIn, and X. Set TechNews as a preferred source in Google for more updates.

Cyber Security News Tags:Adversary-in-the-Middle, China hackers, Cisco Talos, Cybersecurity, DarkNimbus, Linux malware, Malware, network security, ShadowPad, traffic manipulation

Post navigation

Previous Post: China-Linked DKnife Framework Exploits Routers for Attacks
Next Post: RenEngine Loader Bypasses Security with Multi-Stage Attack

Related Posts

Aembit Introduces Identity and Access Management for Agentic AI Aembit Introduces Identity and Access Management for Agentic AI Cyber Security News
Chinese Hackers Exploit Southeast Asian Routers Chinese Hackers Exploit Southeast Asian Routers Cyber Security News
BPFDoor Variants Evade Detection Using Stateless C2 BPFDoor Variants Evade Detection Using Stateless C2 Cyber Security News
Google Rolls Out Long-Awaited @gmail.com Email Change Feature for Users Google Rolls Out Long-Awaited @gmail.com Email Change Feature for Users Cyber Security News
Hackers Weaponizing Telegram Messenger with Dangerous Android Malware to Gain Full System Control Hackers Weaponizing Telegram Messenger with Dangerous Android Malware to Gain Full System Control Cyber Security News
Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware Malicious Document Reader App in Google Play With 50K Downloads Installs Anatsa Malware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark