Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

Women are breaking into the male-dominated Mexican regional music genre

October 27, 2025

Halloween pumpkins can be used for baking, compost or animal feed

October 27, 2025

Daylight saving time ends Sunday in the US

October 27, 2025
Facebook X (Twitter) Instagram
Trending
  • Women are breaking into the male-dominated Mexican regional music genre
  • Halloween pumpkins can be used for baking, compost or animal feed
  • Daylight saving time ends Sunday in the US
  • Japan’s sushi legend in ‘Jiro Dreams of Sushi’ documentary turns 100
  • Louvre heist leaves a cultural wound — and may turn French Crown Jewels into legend
  • By the Numbers: Why trick-or-treaters may bag more gummy candy than chocolate this Halloween
  • Health providers turning to prescriptions to get people outside
  • Poker’s NBA-and-Mafia betting scandal echoes movies, popular culture
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Monday, October 27
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » Chinese APT’s Adversary-in-the-Middle Tool Dissected
Cybersecurity

Chinese APT’s Adversary-in-the-Middle Tool Dissected

By adminMay 1, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 101


Cybersecurity firm ESET has dissected a tool used by a Chinese APT tracked as TheWizards to conduct adversary-in-the-middle (AitM) attacks and deploy a backdoor.

The tool, dubbed Spellbinder, enables AitM attacks and lateral movement in the compromised network. It relies on IPv6 stateless address auto-configuration (SLAAC) spoofing, intercepting packets and redirecting the traffic of various Chinese applications in order to download malicious updates from a server controlled by the attackers.

By hijacking the application’s server communication, TheWizards dropped a downloader that fetched and deployed a modular backdoor dubbed WizardNet, ESET explains.

Linked to Dianke Network Security Technology, a Chinese company also known as UPSEC, and active since at least 2022, TheWizards was seen targeting individuals and organizations in Cambodia, China, Hong Kong, the Philippines, and the United Arab Emirates.

The APT was seen deploying Spellbinder on compromised machines to capture network packets and reply to them, using the WinPcap library.

The tool can target the domains of multiple popular Chinese platforms, including Baidu, Baofeng, Funshion, Kingsoft, Mango TV, Quihoo 360, PPLive, Tencent, Yuodao, Xiaomi, and others.

In late 2024, Spellbinder was used to hijack the update of Tencent QQ software and deploy a downloader to load the WizardNet backdoor in the victim machine’s memory.

The implant supports five commands to fetch and execute .NET modules that expand its functionality, unload them, invoke functions from them, upload a client plugin assembly, and send system information to the attackers.

Advertisement. Scroll to continue reading.

Analysis of the malware used by TheWizards shows that the group is associated with UPSEC, the Chinese company previously identified as the supplier of the DarkNimbus malware (also known as DarkNights), used by the hacking group Earth Minotaur.

“ESET continues tracking TheWizards independently of Earth Minotaur. While both threat actors use DarkNights/DarkNimbus, according to ESET telemetry TheWizards has focused on different targets and uses infrastructure and additional tools (for example, Spellbinder and WizardNet) not observed to be used by Earth Minotaur,” ESET notes.

Related: Chinese APT Mustang Panda Updates, Expands Arsenal

Related: Chinese APT Weaver Ant Targeting Telecom Providers in Asia

Related: Chinese I-Soon Hackers Hit 7 Organizations in Operation FishMedley

Related: Chinese Hacking Group MirrorFace Targeting Europe



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

O2 Service Vulnerability Exposed User Location

May 20, 2025

Madhu Gottumukkala Officially Announced as CISA Deputy Director

May 20, 2025

BreachRx Lands $15 Million as Investors Bet on Breach-Workflow Software

May 19, 2025

Printer Company Procolored Served Infected Software for Months

May 19, 2025

UK Legal Aid Agency Finds Data Breach Following Cyberattack

May 19, 2025

480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

May 19, 2025
Add A Comment
Leave A Reply

Don't Miss
Billionaires

These Are The Billionaires Cutting Checks To Stop Zohran Mamdani

October 24, 2025

Mamdani says billionaires shouldn’t exist. Some of them have put their fortunes to work trying…

These Are The Billionaires Cutting Checks To Stop Zohran Mamdani

October 24, 2025

OpenEvidence’s Daniel Nadler $1.3 Billion Richer In Just Three Months After The AI Startup Hits $6 Billion Valuation

October 20, 2025

Alex Bouaziz On Deel’s Latest Fundraise And Why He’s Not Worried About Litigation

October 20, 2025
Our Picks

Women are breaking into the male-dominated Mexican regional music genre

October 27, 2025

Halloween pumpkins can be used for baking, compost or animal feed

October 27, 2025

Daylight saving time ends Sunday in the US

October 27, 2025

Japan’s sushi legend in ‘Jiro Dreams of Sushi’ documentary turns 100

October 26, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

After Klarna, Zoom’s CEO also uses an AI avatar on quarterly call

May 23, 2025

Anthropic CEO claims AI models hallucinate less than humans

May 22, 2025

Anthropic’s latest flagship AI sure seems to love using the ‘cyclone’ emoji

May 22, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.