Hackers abuse IPv6 networking feature to hijack software updates
ID: ae7bd6ee-26c7-52bc-b00b-1d1044f6b5d9
STIX ID: report--ae7bd6ee-26c7-52bc-b00b-1d1044f6b5d9
Feed Name: Bleeping Computer
ESET attributes a campaign since at least 2022 to a China-aligned APT dubbed "TheWizards" that uses a tool called Spellbinder to spoof IPv6 SLAAC Router Advertisements, force Windows hosts to adopt an attacker-controlled IPv6 gateway, intercept update traffic for numerous Chinese software vendors, and serve malicious updates that install a persistent WizardNet backdoor; infections are staged via a trojanized archive (AVGApplicationFrameHostS.zip) and DLL side-loading with WinPcap. Mitigations include monitoring or disabling IPv6 where not required and watching for the listed file and network indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
