logo

TheWizards Deploy ‘Spellbinder Hacking Tool’ for Global Adversary-in-the-Middle Attack

ID: a3e8e988-58e9-5876-a9f6-879b05407f17

STIX ID: report--a3e8e988-58e9-5876-a9f6-879b05407f17

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2025-04-30

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**ESET discovered a China-aligned APT dubbed “TheWizards” that uses an IPv6 SLAAC spoofing tool called Spellbinder to conduct adversary-in-the-middle attacks and hijack legitimate software updates (notably Tencent QQ) to distribute modular backdoors (WizardNet for Windows and DarkNights for Android), targeting organizations across Asia and the Middle East since 2022 and accompanied by multiple IoCs.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.