TheWizards APT Casts a Spell on Asian Gamblers With Novel Attack
ID: 3994ed06-b8dd-5d63-9793-6639285a8237
STIX ID: report--3994ed06-b8dd-5d63-9793-6639285a8237
Feed Name: Dark Reading
ESET research presented at RSAC 2025 attributes a campaign to a Chinese APT called TheWizards that uses a tool named Spellbinder to perform IPv6 SLAAC spoofing (AitM) to intercept and hijack software update processes for popular Chinese applications, delivering a DLL downloader that leads to the WizardNet modular backdoor; the activity targets gambling companies and customers across multiple countries and shows tooling overlap with Earth Minotaur (including DarkNimbus/DarkNights for Android).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
