×
ItalianoEnglish
Set as default language

Grandangolo Communications

  • Home
  • Company
  • Services
    • Public Relation
    • Digital PR
    • Marketing
    • Lead Generation
    • Events
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages
  • Home
  • Customer Press Room
  • Eset
  • ESET analyzes the tools of the APT Thewizards group, affiliated to China, with objectives in Asia and Middle East

Customer Press Room

ESET analyzes the tools of the APT Thewizards group, affiliated to China, with objectives in Asia and Middle East

by Grandangolo Communications / Wednesday, 07 May 2025 / Published in Eset

ESET Research experts discovered and analyzed Spellbinder and WizardNet, tools used by APT group TheWizards to conduct adversary-in-the-middle attacks and redirect application update traffic to attacker-controlled servers

Researchers of ESET, a global European leader in the cybersecurity market, analyzed Spellbinder, a tool used for lateral movement and to execute adversary-in-the-middle attacks by China-aligned APT group TheWizards. Spellbinder enables these attacks by leveraging stateless address autoconfiguration (SLAAC) spoofing, allowing attackers to redirect legitimate Chinese software update protocols to malicious servers. Legitimate software is thus tricked into downloading and executing malicious components that launch the WizardNet backdoor.

TheWizards has been continuously active since at least 2022 to date and, according to ESET telemetry, is targeting individuals, gambling companies and unidentified entities in the Philippines, Cambodia, the United Arab Emirates, mainland China and Hong Kong.

“We initially discovered and analyzed this tool in 2022 and observed a new version, with some changes, deployed on compromised machines in 2023 and 2024,” says Facundo Muñoz, an ESET researcher who analyzed Spellbinder and WizardNet. “Our research led us to discover a tool designed to perform adversary-in-the-middle attacks via IPv6 SLAAC spoofing, intercepting network communications and sending spoofed responses to redirect traffic to malicious servers and deliver malicious updates to legitimate Chinese software,” explains Muñoz.

The final payload of the attack is a backdoor that ESET has named WizardNet, a modular implant that connects to a remote controller to receive and run .NET modules on the compromised machine. Researchers focused on one of the most recent cases, which occurred in 2024, where the Tencent QQ software update was hijacked. The malicious server sending the update instructions is still active. This variant of WizardNet supports five commands, three of which allow .NET modules to be executed in memory, thus extending functionality on the infected machine.

Links also emerge between TheWizards and the Chinese company Dianke Network Security Technology (also known as UPSEC), which is linked to the DarkNights (also known as DarkNimbus) backdoor. According to the UK NCSC, this backdoor also targets Tibetan and Uyghur communities among its main targets. Although TheWizards uses a different backdoor, WizardNet, the hijacking server is configured to deliver DarkNights to applications being updated on Android devices.

For a more in-depth analysis and technical description of TheWizards tools, please refer to the latest ESET Research blog post “TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks" his WeLiveSecurity.com. To stay updated on the latest news you can follow ESET Research on X (formerly known as Twitter), BlueSky e Mastodon.

About Grandangolo Communications

What you can read next

ESET: North Korea-affiliated Lazarus impersonates Meta on LinkedIn to attack aerospace company in Spain
ESET Research identifies the main countries at risk due to the vulnerabilities of the Log4j platform
ESET Research: Gamaredon intensifies campaigns against Ukraine with updated tools

Customer Press Room

  • ESET Research: FamousSparrow steps up operations in Latin America and hits governments with new backdoor

    The pro-Chinese APT group concentrates its activities...
  • ESET's ultra-fast, high-accuracy threat detection scanner, now available in AWS Marketplace

    The ESET PRIVATE Scanning Solutions suite is available...
  • Arrow Electronics signs distribution agreement with Usercentrics

    Arrow Electronics, a global supplier of technology...
  • Acronis names Denis Cassinerio Vice President South Europe CEE

    In the new role the manager will continue the...
  • SentinelOne enhances Wayfinder's Frontier AI services by integrating OpenAI's Daybreak models

    Advanced cybersecurity services expanded with...

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018

Categories

  • A10
  • abstract
  • Abstract
  • Acronis
  • Ally Consulting
  • Arrow
  • Arrow Electronics
  • Axiante
  • Babel
  • Computer Center
  • Cohesity
  • Italy Cloud Consortium
  • Consys
  • D-Link
  • Eset
  • G.B. Service
  • Habble
  • HiSolution
  • HYCU
  • Icos
  • Imprivate
  • Information Tecnology
  • Innovaway
  • Ivanti
  • Link11
  • MobileIron
  • Netalia
  • Nethive
  • Nexthink
  • Nuvis
  • Praim
  • QAD
  • Qualys
  • Red Hot Cyber
  • Riverbed
  • Saviynt
  • Sensormatic
  • SentinelOne
  • Talent Software
  • Vectra
  • Vectra AI
  • Vertiv

Office printing, digital PR, marketing, lead generation: all projects are born from our passion and expertise, with an inevitable touch of creativity and innovation.

COMPANY

Grandangolo Communications Srl
Via Sardegna 19
20146 Milano
Telephone +39 335 8283393
info@grandangolo.it

I SERVIZI

  • Home
  • Company
  • Services
  • Best Practice
  • Customer Press Room
  • Contacts
  • Languages

CONTACTS

  • Contacts
  • Cookie policy
  • Privacy policy

© 2019 GRANDANGOLO COMMUNICATIONS SRL | P.IVA IT 06394850967 | All rights reserveD.

Powered by Webpowerplus

TOP