Description

A China-aligned APT group known as TheWizards has been linked to a lateral movement tool called Spellbinder, designed to perform adversary-in-the-middle (AitM) attacks using IPv6 SLAAC spoofing. This technique allows attackers to intercept and redirect traffic by mimicking IPv6 routers on a network, particularly targeting Chinese software update mechanisms. Spellbinder enables attackers to serve malicious updates by hijacking legitimate traffic, such as for the popular Sogou Pinyin input method, and replacing it with malware-laden downloads. The delivered payload is a modular backdoor called WizardNet. This method of software update hijacking isn't new. ESET previously reported other Chinese groups like Blackwood and PlushDaemon abusing the same update mechanism to deploy implants such as NSPX30 and LittleDaemon. TheWizards has been active since at least 2022 and focuses on targets in Mainland China, Hong Kong, Cambodia, the UAE, and the Philippines, with victims spanning both individuals and the gambling sector. The initial access vector remains unclear, but infections typically begin with a ZIP archive containing multiple files used to sideload a DLL that launches Spellbinder. Spellbinder leverages the WinPcap library to sniff and manipulate network traffic. It specifically targets DNS requests for a hardcoded list of domains associated with major Chinese platforms like Tencent, Baidu, iQIYI, Xiaomi, and others. For instance, it was observed intercepting DNS queries for Tencent QQ updates and redirecting them to an attacker-controlled IP address, ultimately delivering the WizardNet backdoor capable of executing .NET payloads. Another tool used by TheWizards is DarkNights (aka DarkNimbus), attributed to Earth Minotaur, a separate but possibly related group. The Android version of the hijacking server delivers DarkNights, while Windows systems receive WizardNet. Notably, the malware supply chain points to Sichuan Dianke Network Security Technology Co., Ltd. (UPSEC), suggesting the company acts as a digital quartermaster for TheWizards APT operations.