Close Menu
Daily Guardian
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
What's On

Aircraft runway incursions rise in Canada, but one key metric levels off

April 6, 2026

‘They’re intense’: Transport Canada seeks feedback on bright vehicle headlights

April 6, 2026

HII Teams with GrayMatter Robotics to Integrate Physical AI into Manned and Unmanned Shipbuilding

April 6, 2026

APO Productivity Outlook 2026 Highlights Energy Efficiency as a Driver of Productivity Growth

April 6, 2026

Port Alberni harbour residents say noise pollution is affecting their way of life

April 6, 2026
Facebook X (Twitter) Instagram
Finance Pro
Facebook X (Twitter) Instagram
Daily Guardian
Subscribe
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Lifestyle
  • Health
  • Sports
  • Technology
  • Climate
  • Auto
  • Travel
  • Web Stories
Daily Guardian
Home » ESET Research analyzes tools from the China-aligned TheWizards group, with targets across Asia and the Middle East
Press Release

ESET Research analyzes tools from the China-aligned TheWizards group, with targets across Asia and the Middle East

By News RoomApril 30, 20254 Mins Read
ESET Research analyzes tools from the China-aligned TheWizards group, with targets across Asia and the Middle East
Share
Facebook Twitter LinkedIn Pinterest Email
  • ESET discovered and analyzed both Spellbinder and WizardNet, tools used by the China-aligned TheWizards APT group.
  • Spellbinder is used by the TheWizards to conduct local adversary-in-the-middle attacks and to redirect traffic from updating applications to an attacker-controlled server.
  • That server delivers WizardNet, TheWizards’ signature backdoor, which is being deployed by legitimate Chinese software update mechanisms to victims’ machines.
  • ESET also details the links between TheWizards and the Chinese company Dianke Network Security Technology, also known as UPSEC.

SAN DIEGO, April 30, 2025 (GLOBE NEWSWIRE) — ESET researchers have analyzed Spellbinder, a lateral movement tool used to perform adversary-in-the-middle attacks by the China-aligned threat actor TheWizards. Spellbinder enables adversary-in-the-middle attacks through IPv6 stateless address autoconfiguration spoofing, which allows the attackers to redirect the update protocols of legitimate Chinese software to malicious servers. Then the legitimate software is tricked into downloading and executing the malicious components that launch the backdoor WizardNet.

TheWizards has been constantly active since at least 2022 until the present and, according to ESET telemetry, targets individuals, gambling companies, and unknown entities in the Philippines, Cambodia, the United Arab Emirates, mainland China, and Hong Kong.

“We initially discovered and analyzed this tool in 2022, and observed a new version with a few changes that was deployed to compromised machines in 2023 and 2024,” says ESET researcher Facundo Muñoz, who analyzed Spellbinder and WizardNet. “Our research led us to discover a tool used by the attackers that is designed to perform adversary-in-the-middle attacks using IPv6 SLAAC spoofing to intercept and reply to packets in a network, allowing the attackers to redirect traffic and serve malicious updates to legitimate Chinese software,” explains Muñoz.

The final payload in the attack is a backdoor that we named WizardNet – a modular implant that connects to a remote controller to receive and execute .NET modules on the compromised machine. ESET researchers have focused on one of the latest cases, in 2024, in which the update of Tencent QQ software was hijacked. The malicious server that issues the update instructions is still active. This variant of WizardNet supports five commands, three of which allow it to execute .NET modules in memory, thus extending its functionality on the compromised system.

TheWizards and the Chinese company Dianke Network Security Technology (also known as UPSEC) – supplier of the DarkNights backdoor (also known as DarkNimbus), appear to be linked. According to NCSC UK, this malicious backdoor also has Tibetan and Uyghur communities among its primary targets. While TheWizards uses a different backdoor – the WizardNet, the hijacking server is configured to serve DarkNights to updating applications running on Android devices.

For a more detailed analysis and technical breakdown of TheWizards’ tools, check out the latest ESET Research blogpost “TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

About ESET

ESET® provides cutting-edge digital security to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown — securing businesses, critical infrastructure and individuals. Whether it’s endpoint, cloud or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit www.eset.com or follow our social media, podcasts and blogs.

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/e64e1152-5dee-4ed7-ad08-e0d87d089a16


Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Keep Reading

HII Teams with GrayMatter Robotics to Integrate Physical AI into Manned and Unmanned Shipbuilding

APO Productivity Outlook 2026 Highlights Energy Efficiency as a Driver of Productivity Growth

Michigan Rally House Stores to Reopen with a Wolverines Win

Crypto News: AlphaPepe AI DEX Demo Drops Soon While Bitcoin Price Prediction Forecasts $125K

Bring Your Own Cup Day Returns to 7-Eleven Canada

John Pachnos Introduces Himself with a Fully Formed Vision on “John Pachnos,” Arriving May 15 On Avgonyma Music

Dycom Industries, Inc. Appoints Regina Salazar as Chief Information and Digital Officer

MISTR Founder Tristan Schukraft Joins the Producing Team of Titanique

SynGas OBD Fuel Saver Review 2026: Does This Smart Device Actually Cut Your Fuel Costs?

Editors Picks

‘They’re intense’: Transport Canada seeks feedback on bright vehicle headlights

April 6, 2026

HII Teams with GrayMatter Robotics to Integrate Physical AI into Manned and Unmanned Shipbuilding

April 6, 2026

APO Productivity Outlook 2026 Highlights Energy Efficiency as a Driver of Productivity Growth

April 6, 2026

Port Alberni harbour residents say noise pollution is affecting their way of life

April 6, 2026

Latest News

Lady Gaga cancels final Montreal show hours before performance

April 6, 2026

BC Ferries employees working 7 days a week to maintain vessels: union says

April 6, 2026

Michigan Rally House Stores to Reopen with a Wolverines Win

April 6, 2026
Facebook X (Twitter) Pinterest TikTok Instagram
© 2026 Daily Guardian Canada. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version