For more than five years, a threat actor linked to China appears to have developed and maintained a highly sophisticated network monitoring framework capable of acting as a “gateway” for adversary-in-the-middle (AitM) attacks. The threat has been identified by researchers Cisco Talos, who uncovered an extensive cyberespionage campaign that has been ongoing since at least 2019. The tool, known as DKnife, is not just malware, but a full-fledged monitoring and manipulation platform network trafficdesigned to facilitate the installation and control of backdoors on targeted systems.

What is DKnife and how does it work?
According to Talos, DKnife consists of seven Linux-based implants, which are built for deep packet inspection, traffic tampering, and malware distribution.
See also: Infy team restarts operations with new C2 servers
In other words, it acts as an "intermediate layer" between the user and the internet, allowing attackers to monitor, alter, or even redirect data in real time.
The framework has been active since at least 2019, indicating that this is a long-standing and well-organized cyberespionage operation.
Target mainly Chinese users and IoT devices
Cisco's analysis shows that DKnife is primarily used against Chinese users and platforms, targeting desktops, mobile devices, and IoT endpoints.
The tool has been used to distribute and interact with known backdoors such as:
- ShadowPad
- DarkNimbus
These backdoors give attackers remote access, data collection capabilities, and control of critical system functions.
DarkNimbus and the connection with UPSEC
Of particular interest is the DarkNimbus, also known as DarkNights, which is allegedly provided by the Chinese company UPSEC. UPSEC has previously been associated with the Chinese APT group TheWizards, which is known for developing the Spellbinder, another AitM tool.
See also: Attackers exploit old Windows vulnerability to disable EDR

This reinforces the image of an ecosystem where companies and threat groups may collaborate or share expertise.
Similarities with Spellbinder and shared "genealogy"
Talos identified clear overlaps in tactics, techniques, and procedures (TTPs) between DKnife and Spellbinder.
In fact, the WizardNet has been distributed via DKnife, which suggests – according to the researchers – “a common developmental or functional lineage.”
This means that the tools likely belong to the same business network or come from a common development pipeline.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Traffic monitoring, DNS hijacking and update tampering
DKnife is designed to do much more than just tracking.
Its capabilities include:
- Updating already installed backdoors
- DNS traffic violation
- Interception of updates and Android downloads
- Transfer of user activity to command-and-control servers
Additionally, it can interfere with Windows binaries downloads, install ShadowPad and DarkNimbus , and intercept communications related to antivirus or IT management tools.
See also: DragonForce ransomware targets critical business infrastructure
Credential theft and phishing via compromised connections
One of the most worrying elements is that DKnife can steal credentials from a major Chinese email provider.
According to Talos, the framework can breach encrypted connections, extracting usernames and passwords in plain text.
At the same time, it has the ability to display phishing pages for other services, expanding the range of attacks beyond simple espionage.
Geographic targeting may be broader
Although Talos says the analysis is based on data from a single C&C server, it is possible that the malicious framework is being used in other regions.

WizardNet , for example, has also been detected in countries such as the Philippines, Cambodia, and the United Arab Emirates , indicating that the threat may have an international dimension.
See also: Microsoft: Scanner to detect backdoors in open-weight LLMs
A tool with Chinese ties
Cisco concludes that, based on the language in the code, configuration files, and the ShadowPad payload delivered, DKnife is being used by threat actors linked to China.
The incident is yet another reminder that AitM attacks and sophisticated network implants are now key tools of state-sponsored cyberespionage operations, aiming not only at data but also at complete control of digital communication.
