Friday, September 25, 2026

TheWizards Deploy ‘Spellbinder Hacking Tool’ for Global Adversary-in-the-Middle Attack

ESET researchers have uncovered sophisticated attack techniques employed by a China-aligned threat actor dubbed “TheWizards,” which has been actively targeting entities across Asia and the Middle East since 2022.

The group employs a custom lateral movement tool called Spellbinder that performs adversary-in-the-middle (AitM) attacks using IPv6 SLAAC spoofing, allowing attackers to redirect legitimate software updates to malicious servers.

China-Aligned APT Group

TheWizards has developed a comprehensive attack strategy focused primarily on victims in the Philippines, Cambodia, United Arab Emirates, mainland China, and Hong Kong.

According to ESET telemetry, the group targets individuals, gambling companies, and various organizations across these regions.

Geographical distribution of the victims, according to ESET telemetry

Their attack infrastructure involves deploying Spellbinder on compromised networks to intercept traffic and redirect update protocols from legitimate Chinese software to attacker-controlled servers.

The attackers then deliver WizardNet, their signature backdoor, which functions as a modular implant connecting to remote controllers to execute malicious .NET modules on compromised systems.

In a recent case documented by ESET, the update process of Tencent QQ software was hijacked to deliver the malware.

“Our research led us to discover a tool used by the attackers that is designed to perform adversary-in-the-middle attacks,” explained ESET researcher Facundo Muñoz.

The Spellbinder AitM Mechanism

Spellbinder employs an IPv6 SLAAC spoofing technique that exploits commonly overlooked network misconfigurations in IPv4 and IPv6 coexistence.

The tool sends multicast Router Advertisement packets to “all nodes” on the network, causing Windows machines with IPv6 enabled to autoconfigure using information provided in the RA message.

Illustration of the SLAAC attack carried out by Spellbinder

The attack vector leverages the Network Discovery Protocol in IPv6, with Spellbinder advertising itself as an IPv6-capable router. It provides specific DNS server addresses (240e:56:4000:8000::11 and 240e:56:4000:8000::22) that are part of AS4134 from China Telecom Backbone.

When DNS queries are issued for targeted domains-including popular Chinese platforms like Tencent, Baidu, and others-Spellbinder crafts and sends DNS answer messages redirecting traffic to attacker-controlled IP addresses.

Result of the Windows ipconfig command, before and after running Spellbinder

This technique allows TheWizards to perform stealthy man-in-the-middle attacks without requiring ISP compromise, making it particularly effective for lateral movement within targeted organizations.

ESET’s investigation revealed connections between TheWizards and Sichuan Dianke Network Security Technology (also known as UPSEC), a Chinese cybersecurity company.

While TheWizards primarily uses the WizardNet backdoor for Windows systems, their hijacking server is also configured to deliver a backdoor called DarkNights to Android devices.

According to NCSC UK, UPSEC is linked to malware targeting Tibetan and Uyghur communities. Intelligence Online identified UPSEC as the supplier of the DarkNights backdoor (also known as DarkNimbus), which shares infrastructure with TheWizards’ operations.

The sophisticated nature of TheWizards’ tools and tactics represents a significant threat to organizations worldwide.

Their ability to hijack legitimate software update mechanisms from popular Chinese applications demonstrates an advanced persistent threat capability that can bypass conventional security measures.

The group’s continued evolution of tools like Spellbinder since its initial discovery in 2022 indicates ongoing development and operational activity that security teams should monitor closely.

Indicators of Compromise (IoCs):

SHA-1FilenameESET detection nameDescription
9784A1483B4586EB12D86E549D39CA4BB63871B8minibrowser_shell.dllWin32/Agent.AGNFDownloader component.
4DB38A097AE4D5E70B2F51A8EE13B0C1EE01A2A1Client.exeMSIL/Agent.DMSWizardNet backdoor.
76953E949AC54BE8FF3A68794EF1419E9EF9AFCBipv6.exeWin64/Agent.CAZSpellbinder tool (2022).
DA867188937698C7769861C72F5490CB9C3D4F63N/AWin64/Agent.CAZSpellbinder tool (2023), loaded in memory.
0CBA19B19DF9E2C5EBE55D9DE377D26A1A51B70Awsc.dllWin64/Agent.EUOLoads shellcode from log.dat.
1A8147050AF6F05DEA5FBCA1AE1FF2FFD2B68F9Clog.datWin32/Rozena.BXTShellcode that loads Spellbinder.
2D376ADF44DBD9CF5DB08884E76192D0BC9984C4plugin-audiofirstpiece.mlAndroid/Spy.Agent.EFFZIP archive containing DarkNights for Android.
5B70A853D8E989AD102D639FBF7636B697313ABCclasses.dexAndroid/Spy.Agent.EFFDarkNights for Android.

Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

14-Year-Old Linux Kernel Vulnerability Enables Root Access and Docker Escape

A vulnerability in the Linux kernel’s AF_ALG cryptographic interface,...

ServiceNow Security Flaws Allow Attackers to Execute SQL and Modify Instance Data

ServiceNow has disclosed five vulnerabilities affecting its AI Platform,...

Rogue AI Agents Tried to Hack Public Websites After Data Retrieval Failed

Research from Transluce shows that autonomous AI agents shifted...

CISA Flags WSO2 Security Flaw Under Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

CISA Adds Multiple Check Point Product Flaws to Exploited Vulnerabilities List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Salesforce Agentforce Flaw Enables 0-Click Data Exfiltration via Prompt Injection

Security researchers have revealed a vulnerability chain known as...

Sudo Vulnerability Lets Attackers Bypass Time-Based Authorization Controls

A recently disclosed high-severity vulnerability in Sudo could allow...

Duelbits Hot Wallet Hack Drains $7 Million, Forces Platform Offline

Crypto casino Duelbits has confirmed a cybersecurity breach that...

Related Articles

Recent News