Skip to content
Discovery of DKnife Malware Framework Linked to MOONSHINE Exploit Kit

Discovery of DKnife Malware Framework Linked to MOONSHINE Exploit Kit

First seen 6 Feb 2026, 21:46 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

Cisco Talos researchers discovered a previously hidden malware framework named DKnife while hunting for samples of the DarkNimbus backdoor associated with the MOONSHINE exploit kit. This framework, which features gateway monitoring and adversary-in-the-middle capabilities, was found to communicate with the same command and control server as DarkNimbus. The findings were detailed in a report published on February 5, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 184d ago How this analysis works

More articles in this cluster (11)

Following this threat?

Track DarkNimbus in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed