#WizardNet
"Wizardnet is mostly the same as Mugglenet, but websites just magically respect your DNT setting"

bsky.app/profile/faz....
faz.ms Flo 🔶 @faz.ms · Apr 20
This is just as much a fault of big advertising companies refusing to support DNT. They prefer to drum up hate against regulation, instead of just using the existing technology to comply with the laws with a nice UX. Let's hope the GPC rebrand works better.
en.wikipedia.org/wiki/Do_Not_...
Do Not Track - Wikipedia
en.wikipedia.org
April 20, 2026 at 10:28 AM
Spellbinder intercepts DNS queries associated with update domains for Chinese software. We focus on a recent case in which an update of Tencent QQ was hijacked to deploy TheWizards’ signature backdoor, WizardNet. 4/6
April 30, 2025 at 11:30 AM
WizardNet
wizardnet.net
May 15, 2026 at 3:37 PM
🚨 Chinese APT group ‘TheWizards’ is exploiting IPv6 spoofing with a new tool called #Spellbinder to drop the WizardNet backdoor via hijacked software updates.

Read: hackread.com/chinese-thew...

#Cybersecurity #APT #Malware #IPv6 #WizardNet
Chinese Group TheWizards Exploits IPv6 to Drop WizardNet Backdoor
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
May 5, 2025 at 4:39 PM
Chinese Hackers Abuse IPv6 SLAAC for AitM Attacks via Spellbinder Lateral Movement Tool reconbee.com/chinese-hack...

#chinesehackers #IPv6 #Aitmattack #spellbinder #CyberSecurity
Chinese Hackers Abuse IPv6 SLAAC for AitM Attacks via Spellbinder Lateral Movement Tool
modular backdoor known as WizardNet read more about Chinese Hackers Abuse IPv6 SLAAC for AitM Attacks via Spellbinder Lateral Movement Tool
reconbee.com
April 30, 2025 at 5:53 PM
Notícia da SecurityWeek

"Chinese APT’s Adversary-in-the-Middle Tool Dissected" #bolhasec
Chinese APT's Adversary-in-the-Middle Tool Dissected
ESET has analyzed Spellbinder, the IPv6 SLAAC spoofing tool Chinese APT TheWizards uses to deploy its WizardNet backdoor.
www.securityweek.com
August 31, 2025 at 4:30 PM
Notícia da SecurityWeek

"Chinese APT’s Adversary-in-the-Middle Tool Dissected" #bolhasec
Chinese APT's Adversary-in-the-Middle Tool Dissected
ESET has analyzed Spellbinder, the IPv6 SLAAC spoofing tool Chinese APT TheWizards uses to deploy its WizardNet backdoor.
www.securityweek.com
June 14, 2025 at 7:30 PM
Chinese Hackers Exploit IPv6 Network Features to Hack Software Updates #ChineseActors #ChineseHackers #CyberAttacks
Chinese Hackers Exploit IPv6 Network Features to Hack Software Updates
China-linked group attacks ESET discovered both SpellBinder and WizardNet, tools used by Chinese hackers. A China-based APT group, “The Wizards,” has been linked to a lateral movement tool, Spellbinder, which allows adversary-in-the-middle (AitM) attacks.  It does so via IPv6 stateless address autoconfiguration (SLAAC) spoofing, to roam laterally in the compromised network, blocking packets and redirecting the traffic of legal Chinese software to download malicious updates from a server controlled by threat actors, ESET researchers said to The Hacker News.  About malware WizardNet The attack creates a path for a malicious downloader which is delivered by hacking the software update mechanism linked with Sogou Pinyin. Later, the downloader imitates a conduit to deploy a modular backdoor called WizardNet.  In the past, Chinese hackers have abused Sogou Pinyin’s software update process to install malware. Last year, ESET reported a hacking group called Blackwood that delivered an implant called NSPX30 by abusing the update process of the Chinese input method software app.  This year, the Slovak cybersecurity company found another threat actor called PlushDaemon that exploited the same process to deploy a custom downloader called LittleDaemon.  The scale of the attack The Wizards APT has targeted both individuals and the gambling industry in Hong Kong, Mainland China, Cambodia, the United Arab Emirates, and the Phillippines.  Findings highlight that the Spellbinder IPv6 AitM tool has been active since 2022. A successful attack is followed by the delivery of a ZIP archive which includes four separate files.  After this, the threat actors install “wincap.exe” and perform "AVGApplicationFrameHost.exe," to sideload the DLL. The DLL file then reads shellcode from “log.dat” and runs it in memory, resulting in the launch of Spellbinder.  Not the first time In a 2024 attack incident, the hackers utilized this technique to hack the software update process for Tencent QQ at the DNS level to help a trojanized version deploy WizardNet; a modular backdoor that can receive and run .NET payloads on the victim host. Spellbinder does this by blocking the DNS query for the software update domain ("update.browser.qq[.]com") and releasing a DNS response  “The list of targeted domains belongs to several popular Chinese platforms, such as Tencent, Baidu, Xunlei, Youku, iQIYI, Kingsoft, Mango TV, Funshion, Yuodao, Xiaomi and Xioami's Miui, PPLive, Meitu, Quihoo 360, and Baofeng,” reports The Hacker News. 
dlvr.it
May 8, 2025 at 6:45 PM
TheWizards APT Casts a Spell on Asian Gamblers With Novel Attack
TheWizards APT Casts a Spell on Asian Gamblers With Novel Attack
A SLAAC-spoofing, adversary-in-the-middle campaign is hiding the WizardNet backdoor malware inside updates for legitimate software and popular applications.
www.darkreading.com
April 30, 2025 at 9:10 PM
Chinese Hackers Use IPv6 SLAAC Spoofing to Deliver WizardNet Backdoor
Chinese Hackers Use IPv6 SLAAC Spoofing to Deliver WizardNet Backdoor
Chinese hackers leverage IPv6 SLAAC spoofing to redirect legitimate software updates and infect victims with the modular backdoor WizardNet.
cyberinsider.com
May 1, 2025 at 11:02 AM
Chinese Group TheWizards Exploits IPv6 to Drop WizardNet Backdoor

ESET has discovered Spellbinder, a new tool used by the China-linked cyber espionage group TheWizards to conduct AitM…

#hackernews #news
Chinese Group TheWizards Exploits IPv6 to Drop WizardNet Backdoor
ESET has discovered Spellbinder, a new tool used by the China-linked cyber espionage group TheWizards to conduct AitM…
hackread.com
May 6, 2025 at 4:18 PM
Feed: "CyberInsider"
By: Bill Mann on Thursday, May 1, 2025
Chinese Hackers Use IPv6 SLAAC Spoofing to Deliver WizardNet Backdoor
Chinese hackers leverage IPv6 SLAAC spoofing to redirect legitimate software updates and infect victims with the modular backdoor WizardNet.
cyberinsider.com
May 1, 2025 at 9:24 PM
WizardNet
November 12, 2024 at 5:54 PM
中国の脅威アクターが中間者攻撃(AitM)に「DKnife」インプラントを使用

過去5年以上にわたり、中国と関係する脅威アクターが、バックドアの配布および操作を行うためのゲートウェイ監視と中間者攻撃(AitM)フレームワークを運用してきたと、CiscoのTalos研究者が警告している。 DKnifeと名付けられたこのフレームワークは、ディープパケットインスペクション、トラフィック操作、マルウェア配布を目的に設計された7つのLinuxベースのインプラントで構成され、少なくとも2019年以降活動している。…
中国の脅威アクターが中間者攻撃(AitM)に「DKnife」インプラントを使用
過去5年以上にわたり、中国と関係する脅威アクターが、バックドアの配布および操作を行うためのゲートウェイ監視と中間者攻撃(AitM)フレームワークを運用してきたと、CiscoのTalos研究者が警告している。 DKnifeと名付けられたこのフレームワークは、ディープパケットインスペクション、トラフィック操作、マルウェア配布を目的に設計された7つのLinuxベースのインプラントで構成され、少なくとも2019年以降活動している。 このフレームワークは主に中国語話者のユーザーを標的とし、デスクトップ、モバイル、IoTデバイス上で、ShadowPadやDarkNimbusといったバックドアを配布し、それらとやり取りする。 DarkNimbus(別名DarkNights)は中国企業UPSECが提供しており、同社は以前、中国のAPT「TheWizards」(Spellbinder AitMフレームワークの運用者)との関連が指摘されていた。 Talosによれば、DKnifeとSpellbinderのTTPには重複があり、さらにWizardNetバックドアがDKnifeによって配布されていることから、「共通の開発系統または運用上の系譜」が示唆されるという。 Talosによると、Spellbinderと同様にDKnifeはメールやメッセージングサービスを含む中国のプラットフォームやアプリケーションを標的としている。また、そのコードは中国のメディアサイトにも言及しているという。 しかし同サイバーセキュリティ企業は、分析が単一のコマンド&コントロール(C&C)サーバーの設定ファイルに基づいている点を指摘し、別のサーバーが異なる地域を標的にするために使用されている可能性があるとしている(WizardNetはフィリピン、カンボジア、UAEでも使用されていた)。 DKnifeはネットワークトラフィックを監視・操作し、被害者のシステム上で稼働するバックドアとやり取りするために構築された。バックドアの更新、DNSトラフィックのハイジャック、Androidアプリケーションの更新およびダウンロードのハイジャック、ユーザーの活動のC&Cへの流出が可能だ。 また、Windowsなどのバイナリのダウンロードをハイジャックし、ShadowPadおよびDarkNimbusのバックドアを展開できるほか、アンチウイルスやPC管理製品に関連するトラフィックを傍受・妨害し、ユーザーのネットワーク活動を監視して報告することもできる。 さらに、主要な中国のメールプロバイダーの認証情報を窃取(暗号化接続をハイジャックして平文のユーザー名とパスワードを抽出)でき、他のサービス向けにフィッシングページを提供することも可能だ。 「コード、設定ファイル、そしてキャンペーンで配布されたShadowPadマルウェアで使用されている言語に基づき、中国と関係する脅威アクターがこのツールを運用していると高い確度で評価している」とCiscoは述べている。 翻訳元:
blackhatnews.tokyo
February 6, 2026 at 9:00 AM
Chinese Group TheWizards Exploits IPv6 to Drop WizardNet Backdoor ift.tt/HQjFkc1
Chinese Group TheWizards Exploits IPv6 to Drop WizardNet Backdoor
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
buff.ly
May 6, 2025 at 10:12 PM
Chinese APT's Adversary-in-the-Middle Tool Dissected - SecurityWeek buff.ly/3VJDKz2
Chinese APT’s Adversary-in-the-Middle Tool Dissected
ESET has analyzed Spellbinder, the IPv6 SLAAC spoofing tool Chinese APT TheWizards uses to deploy its WizardNet backdoor.
buff.ly
May 4, 2025 at 7:12 AM
Wizards of Cyber: Spellbinder Casts a Dark Cybersecurity Spell

Discover how TheWizards' Spellbinder tool conducts AitM attacks and spreads WizardNet via fake updates. Learn about this China-linked cyber espionage threat.
thenimblenerd.com?p=1044630
Wizards of Cyber: Spellbinder Casts a Dark Cybersecurity Spell
ESET has uncovered Spellbinder, a tool by TheWizards, a China-linked group. They use it for AitM attacks, redirecting software updates to spread their WizardNet backdoor. Through clever network trickery and fake DNS responses, Spellbinder has a knack for causing mischief while making software updates look like a magic show gone wrong.
thenimblenerd.com
May 5, 2025 at 5:01 PM
TheWizards’ Spellbinder: A Magical Mess for Cybersecurity in Asia

Discover the magic behind TheWizards' Spellbinder tool for AitM attacks. Uncover how ESET reveals their tricks in this cybersecurity caper!
thenimblenerd.com?p=1044332
TheWizards’ Spellbinder: A Magical Mess for Cybersecurity in Asia
ESET has unraveled TheWizards' tricks with Spellbinder, a tool that conducts adversary-in-the-middle attacks and deploys the WizardNet backdoor. By hijacking app traffic, this Chinese APT group spreads chaos across networks in Cambodia, China, and beyond. TheWizards prove that, in the digital realm, modern sorcery is alive and spoofing.
thenimblenerd.com
May 1, 2025 at 11:16 AM
Spellbinder Strikes: TheWizards APT Casts Chaos with Sneaky Software Hijacks

TheWizards APT group uses Spellbinder for AitM attacks, leveraging IPv6 to hijack software updates and deploy malware like WizardNet. Watch your updates—magic isn't always good!
thenimblenerd.com?p=1044224
Spellbinder Strikes: TheWizards APT Casts Chaos with Sneaky Software Hijacks
TheWizards APT group is using Spellbinder to perform adversary-in-the-middle attacks, cleverly hijacking software updates to install their own backdoor. By spoofing IPv6 configurations, they've turned mundane updates into a spellbinding cybersecurity nightmare. It's a magical trick worthy of Hogwarts, but with far less charming consequences.
thenimblenerd.com
April 30, 2025 at 12:37 PM