DarkNimbus
DarkNimbus is a backdoor malware family, also referred to in the content as DarkNights, associated with China-nexus activity. Cisco Talos linked it to the Earth Minotaur threat cluster and reported that it has been tracked since 2023 in connection with mobile exploit delivery. The malware is also described as having been used by the APT group TheWizards, and one report states it was developed by Earth Minotaur.
The content describes DarkNimbus as an Android-and-Windows backdoor delivered through adversary-in-the-middle traffic hijacking operations. In Cisco Talos reporting, the DKnife framework—an AitM toolkit deployed on compromised routers and edge devices since at least 2019—was used to hijack binary downloads and Android application updates to deliver DarkNimbus, often alongside ShadowPad. On Windows, Talos observed a legitimate or signed loader side-loading a ShadowPad DLL, after which ShadowPad loaded DarkNimbus. On Android, DarkNimbus was delivered directly by DKnife through hijacked app updates. DKnife also supported DarkNimbus operations by intercepting DNS requests and rerouting them to the real command-and-control infrastructure so the backdoor could communicate successfully.
DarkNimbus appears in broader China-aligned intrusion ecosystems involving WizardNet and the Spellbinder traffic-hijacking framework. Infrastructure overlap and reporting cited in the content connect DKnife, WizardNet, TheWizards, and Earth Minotaur. Targeting described in the content is focused primarily on Chinese-speaking users, with related activity and linked campaigns affecting sectors and regions including the gambling industry and victims in the Philippines, Cambodia, Hong Kong, Mainland China, the United Arab Emirates, and a Philippine educational institution. The content does not provide standalone DarkNimbus-specific IOCs, but high-confidence associated artifacts include its use with DKnife, ShadowPad, MOONSHINE, WizardNet, and Earth Minotaur-linked infrastructure.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Since 2023, Cisco Talos has tracked the MOONSHINE exploit kit and the DarkNimbus backdoor used to deliver mobile exploits.
"...campaigns involving ShadowPad, DarkNimbus, and the WizardNet backdoor."
...TheWizard APT group, which also deployed DarkNimbus backdoor developed by Earth Minotaur.
Techniques & procedures
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
2 techniques“DKnife hijacks software downloads and Android app updates to spread ShadowPad and DarkNimbus backdoors.”
DKnife hijacks software downloads and Android app updates... It redirects update requests to a local malicious server and replaces legitimate downloads with malware.
Execution
1 techniqueStealth
1 techniqueCredential Access
1 techniqueCollection
1 techniqueCommand and Control
1 technique“Spoof Downloads: It detects when a user tries to download a Windows binary… and swaps it for a malicious installer on the fly.”
Impact
1 techniquedknife.bin – DPI & attack engine... runs attacks such as DNS hijacking, binary and APK download hijacking, and user activity monitoring.
IOCs tracked for this family
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Recent activity
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cross-platform (Android and Windows) backdoor used for long-term surveillance, delivered via MOONSHINE exploit kit.
Backdoor associated with the Earth Minotaur cluster and also referenced as used by the APT group TheWizards; delivered via DKnife-facilitated traffic manipulation.
Backdoor delivered by the DKnife toolkit in this campaign; specific capabilities not described in the provided content.
A backdoor delivered in a chain where ShadowPad is side-loaded first and then loads DarkNimbus; DKnife supports its C2 by intercepting and rerouting DNS requests to the real C2 infrastructure.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.