logo

Hackers abuse IPv6 networking feature to hijack software updates

ID: ae7bd6ee-26c7-52bc-b00b-1d1044f6b5d9

STIX ID: report--ae7bd6ee-26c7-52bc-b00b-1d1044f6b5d9

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-05-01

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

ESET attributes a campaign since at least 2022 to a China-aligned APT dubbed "TheWizards" that uses a tool called Spellbinder to spoof IPv6 SLAAC Router Advertisements, force Windows hosts to adopt an attacker-controlled IPv6 gateway, intercept update traffic for numerous Chinese software vendors, and serve malicious updates that install a persistent WizardNet backdoor; infections are staged via a trojanized archive (AVGApplicationFrameHostS.zip) and DLL side-loading with WinPcap. Mitigations include monitoring or disabling IPv6 where not required and watching for the listed file and network indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.