#TheWizards
#ESETResearch analyzed the toolset of the China-aligned APT group that we have named #TheWizards. It can move laterally on compromised networks by performing adversary-in-the-middle (AitM) attacks to hijack software updates. www.welivesecurity.com/en/eset-rese... 1/6
TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks
ESET researchers publish an analysis of Spellbinder, a lateral movement tool used to perform adversary-in-the-middle attacks.
www.welivesecurity.com
April 30, 2025 at 11:30 AM
THE WIZARDS - "Rise of the Serpent" (2018)

#heavymetal #stonerrock #hardrock #doommetal #occultrock #thewizards
May 13, 2025 at 11:58 AM
In our blogpost, we also discuss links we uncovered between #TheWizards and the Chinese company Dianke Network Security Technology, also known as UPSEC. 5/6
April 30, 2025 at 11:30 AM
IoCs available in our GitHub repo: github.com/eset/malware... 6/6
malware-ioc/thewizards at master · eset/malware-ioc
Indicators of Compromises (IOC) of our various investigations - eset/malware-ioc
github.com
April 30, 2025 at 11:30 AM
A China-aligned APT threat actor named "TheWizards" abuses an IPv6 networking feature to launch adversary-in-the-middle (AitM) attacks that hijack software updates to install Windows malware.
Hackers abuse IPv6 networking feature to hijack software updates
A China-aligned APT threat actor named "TheWizards" abuses an IPv6 networking feature to launch adversary-in-the-middle (AitM) attacks that hijack software updates to install Windows malware.
www.bleepingcomputer.com
May 1, 2025 at 12:33 AM
#TheWizards deploy a tool we have named #Spellbinder, which implements IPv6 SLAAC spoofing to redirect IPv6 traffic to the machine running Spellbinder, making it act as a malicious IPv6-capable router. 3/6
April 30, 2025 at 11:30 AM
Spellbinder intercepts DNS queries associated with update domains for Chinese software. We focus on a recent case in which an update of Tencent QQ was hijacked to deploy TheWizards’ signature backdoor, WizardNet. 4/6
April 30, 2025 at 11:30 AM
Arrived in DC with my cousin for a girls trip to take a mental break and revisiting life at 57 on my own terms. #protectingmypeace and #energy #fightingcancerwithasmile
#nomakeup #dc #girlstrip #thewizards #champagne #mimosas #smithsonianafricanamericanmuseum #basketball #ronaldreaganairport
November 25, 2024 at 7:14 AM
Extrait de l'album "Deeper Revolution" sorti sur le label L'assos'piquante en 2009.
tilala.net
#MoKalamity #TheWizards #Reggae #webradio #tilala
Without Faith Nor Law
YouTube video by Mo'Kalamity - Topic
youtu.be
March 23, 2026 at 6:37 AM
🚨 APT group TheWizards exploits IPv6 to hijack software updates

China-aligned threat actor, "TheWizards," is abusing IPv6's SLAAC feature to launch adversary-in-the-middle attacks, redirecting software updates to install malware.

#ransomNews #CyberSecurity #APT #IPv6
Hackers abuse IPv6 networking feature to hijack software updates
A China-aligned APT threat actor named "TheWizards" abuses an IPv6 networking feature to launch adversary-in-the-middle (AitM) attacks that hijack software updates to install Windows malware.
www.bleepingcomputer.com
May 2, 2025 at 1:35 PM
🚨 Chinese APT group ‘TheWizards’ is exploiting IPv6 spoofing with a new tool called #Spellbinder to drop the WizardNet backdoor via hijacked software updates.

Read: hackread.com/chinese-thew...

#Cybersecurity #APT #Malware #IPv6 #WizardNet
Chinese Group TheWizards Exploits IPv6 to Drop WizardNet Backdoor
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
May 5, 2025 at 4:39 PM
ESET researchers provide an analysis of Spellbinder, a lateral movement tool for performing adversary-in-the-middle attacks, used by TheWizards, a China-aligned threat actor. www.welivesecurity.com/en/eset-rese...
May 1, 2025 at 10:07 AM
Hackers abuse IPv6 networking feature to hijack software updates
Hackers abuse IPv6 networking feature to hijack software updates
A China-aligned APT threat actor named "TheWizards" abuses an IPv6 networking feature to launch adversary-in-the-middle (AitM) attacks that hijack software updates to install Windows malware.
www.bleepingcomputer.com
May 1, 2025 at 12:59 AM
Tras 12 años de trayectoria los bilbaínos #TheWizards anuncian el fin de su actividad. A través del siguiente comunicado se despiden y convocan a sus seguidores a acudir a los últimos 3 conciertos.

heavymetalbrigade.wordpress.com/2025/07/27/t...
The Wizards: Fin Del Camino
Tras 12 años de trayectoria los bilbaínos The Wizards anuncian el fin de su actividad. A través del siguiente comunicado se despiden y convocan a sus seguidores a acudir a los últimos 3 conciertos …
heavymetalbrigade.wordpress.com
July 27, 2025 at 8:14 AM
A recent report reveals that Chinese hackers exploit weaknesses in how devices connect to the Internet, specifically a flaw in IPv6 protocols, to conduct large-scale cyberattacks. Stronger laws are needed to protect Arizonans from cyber threats undermining our economy and freedom.

#Arizona7 #Tucson
TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks
ESET researchers publish an analysis of Spellbinder, a lateral movement tool used to perform adversary-in-the-middle attacks.
www.welivesecurity.com
April 30, 2025 at 6:57 PM
Notícia da BleepingComputer

"Hackers abuse IPv6 networking feature to hijack software updates" #bolhasec
Hackers abuse IPv6 networking feature to hijack software updates
A China-aligned APT threat actor named "TheWizards" abuses an IPv6 networking feature to launch adversary-in-the-middle (AitM) attacks that hijack software updates to install Windows malware.
www.bleepingcomputer.com
September 4, 2025 at 3:30 PM
Notícia da SecurityWeek

"Chinese APT’s Adversary-in-the-Middle Tool Dissected" #bolhasec
Chinese APT's Adversary-in-the-Middle Tool Dissected
ESET has analyzed Spellbinder, the IPv6 SLAAC spoofing tool Chinese APT TheWizards uses to deploy its WizardNet backdoor.
www.securityweek.com
August 31, 2025 at 4:30 PM
Notícia da SecurityWeek

"Chinese APT’s Adversary-in-the-Middle Tool Dissected" #bolhasec
Chinese APT's Adversary-in-the-Middle Tool Dissected
ESET has analyzed Spellbinder, the IPv6 SLAAC spoofing tool Chinese APT TheWizards uses to deploy its WizardNet backdoor.
www.securityweek.com
June 14, 2025 at 7:30 PM
Notícia da BleepingComputer

"Hackers abuse IPv6 networking feature to hijack software updates" #bolhasec
Hackers abuse IPv6 networking feature to hijack software updates
A China-aligned APT threat actor named "TheWizards" abuses an IPv6 networking feature to launch adversary-in-the-middle (AitM) attacks that hijack software updates to install Windows malware.
www.bleepingcomputer.com
June 4, 2025 at 8:30 PM
really need to take the CCNA proper / wonder if work reimburses me for certs 🧐
TheWizards APT Uses Spellbinder for Man-in-the-Middle Attacks via IPv6 - Tech News
Chinese APT group TheWizards uses Spellbinder to intercept traffic and deliver malware by manipulating IPv6 and Sogou Pinyin updates.
securityexpress.info
May 3, 2025 at 4:36 AM