
Security researchers at ESET have uncovered a China-aligned advanced persistent threat (APT) group called TheWizards using a lateral movement tool named Spellbinder. This sophisticated tool enables adversary-in-the-middle (AitM) attacks through IPv6 stateless address autoconfiguration (SLAAC) spoofing.
According to ESET researcher Facundo Muñoz, “Spellbinder intercepts packets and redirects traffic of legitimate Chinese software so that it downloads malicious updates from attacker-controlled servers.” The attack hijacks software update mechanisms, particularly those of Sogou Pinyin, to deliver a malicious downloader that subsequently deploys a modular backdoor called WizardNet.
This technique isn’t unprecedented among Chinese threat actors. Earlier in 2024, ESET identified two other groups—Blackwood and PlushDaemon—exploiting Sogou Pinyin’s update process to distribute malware.
TheWizards APT primarily targets individuals and gambling sectors across Cambodia, Hong Kong, Mainland China, the Philippines, and the United Arab Emirates. Evidence suggests Spellbinder has been operational since at least 2022.
The attack chain begins with the delivery of a ZIP archive containing four files: AVGApplicationFrameHost.exe, wsc.dll, log.dat, and winpcap.exe. After installation, the DLL reads shellcode from log.dat and executes it in memory, launching Spellbinder.
“Spellbinder uses the WinPcap library to capture packets and exploits IPv6’s Network Discovery Protocol,” Muñoz explained. In a 2024 attack, the group hijacked Tencent QQ’s update process at the DNS level, redirecting update requests to an attacker-controlled server hosting a trojanized version that deployed WizardNet.
Another tool in TheWizards’ arsenal is DarkNights (also known as DarkNimbus), which has been linked to a Chinese public security ministry contractor named Sichuan Dianke Network Security Technology Co., Ltd. While TheWizards uses WizardNet for Windows systems, their hijacking server is configured to serve DarkNights to Android devices, suggesting Dianke Network Security serves as a “digital quartermaster” for the APT group.
