ESET Research experts discovered and analyzed Spellbinder and WizardNet, tools used by APT group TheWizards to conduct adversary-in-the-middle attacks and redirect application update traffic to attacker-controlled servers
Researchers of ESET, a global European leader in the cybersecurity market, analyzed Spellbinder, a tool used for lateral movement and to execute adversary-in-the-middle attacks by China-aligned APT group TheWizards. Spellbinder enables these attacks by leveraging stateless address autoconfiguration (SLAAC) spoofing, allowing attackers to redirect legitimate Chinese software update protocols to malicious servers. Legitimate software is thus tricked into downloading and executing malicious components that launch the WizardNet backdoor.
TheWizards has been continuously active since at least 2022 to date and, according to ESET telemetry, is targeting individuals, gambling companies and unidentified entities in the Philippines, Cambodia, the United Arab Emirates, mainland China and Hong Kong.
“We initially discovered and analyzed this tool in 2022 and observed a new version, with some changes, deployed on compromised machines in 2023 and 2024,” says Facundo Muñoz, an ESET researcher who analyzed Spellbinder and WizardNet. “Our research led us to discover a tool designed to perform adversary-in-the-middle attacks via IPv6 SLAAC spoofing, intercepting network communications and sending spoofed responses to redirect traffic to malicious servers and deliver malicious updates to legitimate Chinese software,” explains Muñoz.
The final payload of the attack is a backdoor that ESET has named WizardNet, a modular implant that connects to a remote controller to receive and run .NET modules on the compromised machine. Researchers focused on one of the most recent cases, which occurred in 2024, where the Tencent QQ software update was hijacked. The malicious server sending the update instructions is still active. This variant of WizardNet supports five commands, three of which allow .NET modules to be executed in memory, thus extending functionality on the infected machine.
Links also emerge between TheWizards and the Chinese company Dianke Network Security Technology (also known as UPSEC), which is linked to the DarkNights (also known as DarkNimbus) backdoor. According to the UK NCSC, this backdoor also targets Tibetan and Uyghur communities among its main targets. Although TheWizards uses a different backdoor, WizardNet, the hijacking server is configured to deliver DarkNights to applications being updated on Android devices.
For a more in-depth analysis and technical description of TheWizards tools, please refer to the latest ESET Research blog post “TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks" his WeLiveSecurity.com. To stay updated on the latest news you can follow ESET Research on X (formerly known as Twitter), BlueSky e Mastodon.






