TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks
ID: 0c73a7c2-1ebc-51ac-96c5-d91acd119458
STIX ID: report--0c73a7c2-1ebc-51ac-96c5-d91acd119458
Feed Name: WeLiveSecurity (ESET Research)
Threat Score
ESET researchers detail TheWizards, a China-aligned APT active since at least 2022, which uses a custom IPv6 SLAAC adversary‑in‑the‑middle tool named Spellbinder to hijack legitimate Chinese software updates and deliver a modular backdoor called WizardNet; the report includes technical analysis, execution chains, victim geography, IoCs (files and network), MITRE mappings, and links to infrastructure and a suspected supplier (UPSEC).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
