216.73.216.6

Knife Cutting the Edge: Disclosing a China-nexus gateway-monitoring AitM framework

· Published 05/02/2026 20:16 · Modified 06/02/2026 16:58

Export JSON

Essential information

Published
05/02/2026 20:16
Modified
06/02/2026 16:58
Tags
2026-02-05 aitm china-nexus darknimbus dknife dns hijacking gateway-monitoring poisonplug.shadow shadowpad traffic manipulation wizardnet
Related entities
80 observables, 1 intrusion sets (apt), 4 malware, 4 others

Description

Cisco Talos uncovered '', a sophisticated and adversary-in-the-middle () framework comprising seven Linux-based implants. Used since 2019, performs deep-packet inspection, , and malware delivery via routers and edge devices. It targets various devices, including PCs, mobile devices, and IoT, delivering and backdoors. The framework primarily targets Chinese-speaking users, with evidence suggesting threat actors as operators. 's capabilities include , Android application update hijacking, Windows binary hijacking, anti-virus traffic disruption, and user activity monitoring. A link to the campaign was also discovered, indicating a shared development or operational lineage.

External references