TI Mindmap HUB
Threat Intelligence Report

Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework

📅 February 6, 2026 📰 blog.talosintelligence.com 🔍 0 CVE(s) referenced

Cisco Talos uncovered “DKnife,” an advanced China-linked adversary-in-the-middle (AitM) framework active since at least 2019, which uses modular Linux implants to hijack and manipulate traffic at the gateway level, exfiltrate sensitive user data, and deliver malware—including ShadowPad and DarkNimbus—primarily targeting Chinese-speaking users via routers and edge devices.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle