Infosecurity-Magazine
Discovery of DKnife Malware Framework Linked to MOONSHINE Exploit Kit
First seen 6 Feb 2026, 21:46 UTC
•



+5
•88% similarity
•39.0
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Cisco Talos researchers discovered a previously hidden malware framework named DKnife while hunting for samples of the DarkNimbus backdoor associated with the MOONSHINE exploit kit. This framework, which features gateway monitoring and adversary-in-the-middle capabilities, was found to communicate with the same command and control server as DarkNimbus. The findings were detailed in a report published on February 5, 2026.
ThreatCluster AI
How this analysis works