logo

TheWizards APT Casts a Spell on Asian Gamblers With Novel Attack

ID: 3994ed06-b8dd-5d63-9793-6639285a8237

STIX ID: report--3994ed06-b8dd-5d63-9793-6639285a8237

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2025-04-30

Date Updated: 2026-04-21

Author: Tara Seals

...
...

ESET research presented at RSAC 2025 attributes a campaign to a Chinese APT called TheWizards that uses a tool named Spellbinder to perform IPv6 SLAAC spoofing (AitM) to intercept and hijack software update processes for popular Chinese applications, delivering a DLL downloader that leads to the WizardNet modular backdoor; the activity targets gambling companies and customers across multiple countries and shows tooling overlap with Earth Minotaur (including DarkNimbus/DarkNights for Android).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.