logo

TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks

ID: 0c73a7c2-1ebc-51ac-96c5-d91acd119458

STIX ID: report--0c73a7c2-1ebc-51ac-96c5-d91acd119458

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
90/100

Date Published: 2025-04-30

Date Updated: 2026-05-01

...
...

ESET researchers detail TheWizards, a China-aligned APT active since at least 2022, which uses a custom IPv6 SLAAC adversary‑in‑the‑middle tool named Spellbinder to hijack legitimate Chinese software updates and deliver a modular backdoor called WizardNet; the report includes technical analysis, execution chains, victim geography, IoCs (files and network), MITRE mappings, and links to infrastructure and a suspected supplier (UPSEC).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.