Discovery of DKnife Malware Framework Linked to MOONSHINE Exploit Kit

Discovery of DKnife Malware Framework Linked to MOONSHINE Exploit Kit

First seen 6 Feb 2026, 21:46 UTC Blog.TalosintelligenceGbhackersThehackernewsInfosecurity-MagazineBleepingcomputer+5 88% similarity 39.0

Article Content

Browse articles
ThreatCluster

Cisco Talos researchers discovered a previously hidden malware framework named DKnife while hunting for samples of the DarkNimbus backdoor associated with the MOONSHINE exploit kit. This framework, which features gateway monitoring and adversary-in-the-middle capabilities, was found to communicate with the same command and control server as DarkNimbus. The findings were detailed in a report published on February 5, 2026.

ThreatCluster AI How this analysis works

Community

Browse all →