Close Menu
World Forbes – Business, Tech, AI & Global Insights
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
What's Hot

What to Stream: Reneé Rapp, Anthony Mackie and Jason Momoa

July 28, 2025

Trump calls for DC to restore old NFL name as experts say Native mascots cause harm

July 27, 2025

What to know about the dating app Tea and its hacked data

July 26, 2025
Facebook X (Twitter) Instagram
Trending
  • What to Stream: Reneé Rapp, Anthony Mackie and Jason Momoa
  • Trump calls for DC to restore old NFL name as experts say Native mascots cause harm
  • What to know about the dating app Tea and its hacked data
  • If you don’t have diabetes, do you really need a continuous glucose monitor?
  • Blue Ivy shines on stage during Beyoncé’s Cowboy Carter tour
  • Judge pauses cancellation of humanities grants
  • African Americans move to Kenya to connect with heritage and culture
  • ‘South Park’ Creators Trey Parker and Matt Stone Are Now Billionaires
World Forbes – Business, Tech, AI & Global InsightsWorld Forbes – Business, Tech, AI & Global Insights
Monday, July 28
  • Home
  • AI
  • Billionaires
  • Business
  • Cybersecurity
  • Education
    • Innovation
  • Money
  • Small Business
  • Sports
  • Trump
World Forbes – Business, Tech, AI & Global Insights
Home » Chinese APT’s Adversary-in-the-Middle Tool Dissected
Cybersecurity

Chinese APT’s Adversary-in-the-Middle Tool Dissected

adminBy adminMay 1, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email
Post Views: 44


Cybersecurity firm ESET has dissected a tool used by a Chinese APT tracked as TheWizards to conduct adversary-in-the-middle (AitM) attacks and deploy a backdoor.

The tool, dubbed Spellbinder, enables AitM attacks and lateral movement in the compromised network. It relies on IPv6 stateless address auto-configuration (SLAAC) spoofing, intercepting packets and redirecting the traffic of various Chinese applications in order to download malicious updates from a server controlled by the attackers.

By hijacking the application’s server communication, TheWizards dropped a downloader that fetched and deployed a modular backdoor dubbed WizardNet, ESET explains.

Linked to Dianke Network Security Technology, a Chinese company also known as UPSEC, and active since at least 2022, TheWizards was seen targeting individuals and organizations in Cambodia, China, Hong Kong, the Philippines, and the United Arab Emirates.

The APT was seen deploying Spellbinder on compromised machines to capture network packets and reply to them, using the WinPcap library.

The tool can target the domains of multiple popular Chinese platforms, including Baidu, Baofeng, Funshion, Kingsoft, Mango TV, Quihoo 360, PPLive, Tencent, Yuodao, Xiaomi, and others.

In late 2024, Spellbinder was used to hijack the update of Tencent QQ software and deploy a downloader to load the WizardNet backdoor in the victim machine’s memory.

The implant supports five commands to fetch and execute .NET modules that expand its functionality, unload them, invoke functions from them, upload a client plugin assembly, and send system information to the attackers.

Advertisement. Scroll to continue reading.

Analysis of the malware used by TheWizards shows that the group is associated with UPSEC, the Chinese company previously identified as the supplier of the DarkNimbus malware (also known as DarkNights), used by the hacking group Earth Minotaur.

“ESET continues tracking TheWizards independently of Earth Minotaur. While both threat actors use DarkNights/DarkNimbus, according to ESET telemetry TheWizards has focused on different targets and uses infrastructure and additional tools (for example, Spellbinder and WizardNet) not observed to be used by Earth Minotaur,” ESET notes.

Related: Chinese APT Mustang Panda Updates, Expands Arsenal

Related: Chinese APT Weaver Ant Targeting Telecom Providers in Asia

Related: Chinese I-Soon Hackers Hit 7 Organizations in Operation FishMedley

Related: Chinese Hacking Group MirrorFace Targeting Europe



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

O2 Service Vulnerability Exposed User Location

May 20, 2025

Madhu Gottumukkala Officially Announced as CISA Deputy Director

May 20, 2025

BreachRx Lands $15 Million as Investors Bet on Breach-Workflow Software

May 19, 2025

Printer Company Procolored Served Infected Software for Months

May 19, 2025

UK Legal Aid Agency Finds Data Breach Following Cyberattack

May 19, 2025

480,000 Catholic Health Patients Impacted by Serviceaide Data Leak

May 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Don't Miss
Billionaires

‘South Park’ Creators Trey Parker and Matt Stone Are Now Billionaires

July 25, 2025

After signing a new $1.5 billion deal with Paramount, Trey Parker and Matt Stone are…

How Jeffrey Epstein Got So Rich

July 25, 2025

Vanta Raises Funds At $4 Billion Valuation—Despite Not Needing Cash

July 23, 2025

Former Citigroup Chair Sandy Weill’s New $100 Million Gift To Harness AI For A West Coast Cancer Hub

July 23, 2025
Our Picks

What to Stream: Reneé Rapp, Anthony Mackie and Jason Momoa

July 28, 2025

Trump calls for DC to restore old NFL name as experts say Native mascots cause harm

July 27, 2025

What to know about the dating app Tea and its hacked data

July 26, 2025

If you don’t have diabetes, do you really need a continuous glucose monitor?

July 26, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to World-Forbes.com
At World-Forbes.com, we bring you the latest insights, trends, and analysis across various industries, empowering our readers with valuable knowledge. Our platform is dedicated to covering a wide range of topics, including sports, small business, business, technology, AI, cybersecurity, and lifestyle.

Our Picks

After Klarna, Zoom’s CEO also uses an AI avatar on quarterly call

May 23, 2025

Anthropic CEO claims AI models hallucinate less than humans

May 22, 2025

Anthropic’s latest flagship AI sure seems to love using the ‘cyclone’ emoji

May 22, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 world-forbes. Designed by world-forbes.

Type above and press Enter to search. Press Esc to cancel.