Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Threat Actor Uses DKnife Implant for Attacks

Chinese Threat Actor Uses DKnife Implant for Attacks

Posted on February 6, 2026 By CWS

Over the past several years, a threat actor with ties to China has been actively employing a sophisticated framework designed for adversary-in-the-middle (AitM) attacks. According to researchers from Cisco’s Talos, this framework is used to monitor gateways and deliver backdoors, highlighting its significant threat potential.

DKnife Framework and Its Components

The framework, known as DKnife, comprises seven Linux-based implants. These implants are engineered for deep packet inspection, traffic manipulation, and the distribution of malware. Active since at least 2019, the framework specifically targets users who speak Chinese, making it a focused tool in the digital attack arsenal.

DKnife interacts with backdoors like ShadowPad and DarkNimbus, adapting to a variety of devices including desktop computers, mobile phones, and IoT devices. DarkNimbus, also referred to as DarkNights, is associated with UPSEC, a Chinese firm previously linked to the APT group TheWizards, which operates the Spellbinder AitM framework.

Connections and Targeting Strategies

There are notable similarities between the operational methods of DKnife and Spellbinder, with the WizardNet backdoor being a common element distributed by DKnife. This suggests a potential shared development lineage or operational strategy between these frameworks. DKnife’s primary targets are Chinese platforms and applications, including email and messaging services, with its code referencing Chinese media websites.

Despite this targeted approach, Talos researchers caution that their findings are based on data from a single command-and-control (C&C) server. It is possible that other servers could target different regions, as indicated by the use of WizardNet in countries like the Philippines, Cambodia, and the UAE.

Capabilities and Implications of DKnife

DKnife is capable of extensive network traffic monitoring and manipulation, interacting directly with backdoors on compromised systems. It can update these backdoors, hijack DNS traffic, intercept Android application updates, and exfiltrate user activity to its C&C server. Moreover, it can disrupt traffic associated with antivirus and PC management tools, as well as intercept and monitor user network activity.

In addition, DKnife can steal credentials from a major Chinese email provider by intercepting encrypted connections to extract usernames and passwords. It also serves phishing pages to capture credentials for other services. Cisco’s high-confidence assessment attributes the operation of DKnife to China-based threat actors, based on the language and configuration files observed.

The implications of such advanced cyber threats are significant, underscoring the need for heightened vigilance and robust cybersecurity measures. As these threat actors continue to evolve, organizations must remain proactive in safeguarding their networks against such sophisticated attacks.

Security Week News Tags:AitM attacks, APT TheWizards, Backdoors, Chinese threat, Cisco Talos, Cybersecurity, DarkNimbus, DKnife implant, malware delivery, network traffic, ShadowPad, UPSEC

Post navigation

Previous Post: Hackers Exploit Screensavers for Remote Access
Next Post: Spam Campaign Utilizes Fake PDFs for Remote Access

Related Posts

Chainguard Raises 0 Million in Growth Funding Chainguard Raises $280 Million in Growth Funding Security Week News
Critical VMware Aria Operations Flaw Actively Targeted Critical VMware Aria Operations Flaw Actively Targeted Security Week News
160,000 Impacted by Wayne Memorial Hospital Data Breach 160,000 Impacted by Wayne Memorial Hospital Data Breach Security Week News
Two Scattered Spider Suspects Arrested in UK; One Charged in US Two Scattered Spider Suspects Arrested in UK; One Charged in US Security Week News
Dux Emerges From Stealth Mode With  Million in Funding Dux Emerges From Stealth Mode With $9 Million in Funding Security Week News
Critical Vulnerability in n8n Poses Server Risks Critical Vulnerability in n8n Poses Server Risks Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark