Connect with us

Press Releases

ESET Research analyzes tools from the China-aligned TheWizards group, with targets across Asia and the Middle East

Published

on

eset-research-analyzes-tools-from-the-china-aligned-thewizards-group,-with-targets-across-asia-and-the-middle-east

ESET researchers have analyzed Spellbinder, a lateral movement tool used to perform adversary-in-the-middle attacks by the China-aligned threat actor TheWizards. Spellbinder enables adversary-in-the-middle attacks through IPv6 stateless address autoconfiguration spoofing, which allows the attackers to redirect the update protocols of legitimate Chinese software to malicious servers. Then the legitimate software is tricked into downloading and executing the malicious components that launch the backdoor WizardNet.

TheWizards has been constantly active since at least 2022 until the present and, according to ESET telemetry, targets individuals, gambling companies, and unknown entities in the Philippines, Cambodia, the United Arab Emirates, mainland China, and Hong Kong.

“We initially discovered and analyzed this tool in 2022, and observed a new version with a few changes that was deployed to compromised machines in 2023 and 2024,” says ESET researcher Facundo Muñoz, who analyzed Spellbinder and WizardNet. “Our research led us to discover a tool used by the attackers that is designed to perform adversary-in-the-middle attacks using IPv6 SLAAC spoofing to intercept and reply to packets in a network, allowing the attackers to redirect traffic and serve malicious updates to legitimate Chinese software,” explains Muñoz.

The final payload in the attack is a backdoor that we named WizardNet – a modular implant that connects to a remote controller to receive and execute .NET modules on the compromised machine. ESET researchers have focused on one of the latest cases, in 2024, in which the update of Tencent QQ software was hijacked. The malicious server that issues the update instructions is still active. This variant of WizardNet supports five commands, three of which allow it to execute .NET modules in memory, thus extending its functionality on the compromised system.

TheWizards and the Chinese company Dianke Network Security Technology (also known as UPSEC) – supplier of the DarkNights backdoor (also known as DarkNimbus), appear to be linked. According to NCSC UK, this malicious backdoor also has Tibetan and Uyghur communities among its primary targets. While TheWizards uses a different backdoor – the WizardNet, the hijacking server is configured to serve DarkNights to updating applications running on Android devices.

The post ESET Research analyzes tools from the China-aligned TheWizards group, with targets across Asia and the Middle East appeared first on Gaming and Gambling Industry in the Americas.

Gaming Americas is a news portal providing in-depth news and press release coverage about the gaming industry in North America, Latin America, and South America. Besides the news coverage, the team also hosts boutique-style summits in Europe and North America.

Continue Reading
Advertisement

GamingNewsRoom.com – The Pulse of the Global Gaming Industry

GamingNewsRoom.com cuts through the noise and delivers what the industry actually needs: fast, sharp, and relevant updates from across the gaming universe. Powered by HIPTHER, this platform brings clarity, insight, and a bit of edge to a world overflowing with press releases and recycled headlines.

Real News. Real Insights. Zero Fluff.

With a rapidly growing audience of industry professionals, operators, suppliers, regulators, and tech innovators, GamingNewsRoom.com serves up in-depth stories, analysis, and timely coverage that keeps the global gaming community in the loop. We follow the trends that matter:

  • iGaming & Land-Based Gaming
  • Sports Betting & Esports
  • Regulation, Compliance & Market Movements
  • Technology, AI, Web3 & Future-Ready Innovation

From rapid-fire news briefs to deeper investigative pieces, interviews, opinion columns, and event reporting, GamingNewsRoom.com brings a modern, dynamic perspective to every corner of the industry.

A Platform That Brings the Industry Together

GamingNewsRoom.com doesn’t stop at publishing. Through extensive coverage of HIPTHER’s conferences, virtual discussions, meetups, and global insights, we act as a bridge between leaders, innovators, regulators, and rising talent. It’s where the stories happen — and where the industry connects.

Why GamingNewsRoom.com?

Because the industry deserves a news hub that’s fresh, fast, and unfiltered. Backed by HIPTHER’s decade-long legacy of empowering communities through events, media, and knowledge, GamingNewsRoom.com is built to be your daily checkpoint for what’s shaping the future of gaming worldwide.

Get In Touch

Want to collaborate, submit news, or explore partnerships? We're here for it.

Sales & Partnerships: [email protected]
Editorial / PR Submissions: [email protected]

Copyright © 2015 - 2025
GamingNewsRoom.com is proudly part of HIPTHER. Registered in Estonia under HIPTHER OÜ, Registration no.: 17339889, EU VAT ID: EE102909106.

A decade of innovation — and yes, we’re just getting started. The future isn’t waiting, and neither are we.

Please turn AdBlock off