Saturday, May 2, 2026
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

ESET Research analyzes tools from the China-aligned TheWizards group, with targets across Asia and the Middle East

April 30, 2025
in Artificial Intelligence, GlobeNewswire, Web3
Reading Time: 6 mins read
5
SHARES
247
VIEWS
Share on TwitterShare on LinkedInShare on Facebook
  • ESET discovered and analyzed both Spellbinder and WizardNet, tools used by the China-aligned TheWizards APT group.
  • Spellbinder is used by the TheWizards to conduct local adversary-in-the-middle attacks and to redirect traffic from updating applications to an attacker-controlled server.
  • That server delivers WizardNet, TheWizards’ signature backdoor, which is being deployed by legitimate Chinese software update mechanisms to victims’ machines.
  • ESET also details the links between TheWizards and the Chinese company Dianke Network Security Technology, also known as UPSEC.

SAN DIEGO, April 30, 2025 (GLOBE NEWSWIRE) — ESET researchers have analyzed Spellbinder, a lateral movement tool used to perform adversary-in-the-middle attacks by the China-aligned threat actor TheWizards. Spellbinder enables adversary-in-the-middle attacks through IPv6 stateless address autoconfiguration spoofing, which allows the attackers to redirect the update protocols of legitimate Chinese software to malicious servers. Then the legitimate software is tricked into downloading and executing the malicious components that launch the backdoor WizardNet.

TheWizards has been constantly active since at least 2022 until the present and, according to ESET telemetry, targets individuals, gambling companies, and unknown entities in the Philippines, Cambodia, the United Arab Emirates, mainland China, and Hong Kong.

“We initially discovered and analyzed this tool in 2022, and observed a new version with a few changes that was deployed to compromised machines in 2023 and 2024,” says ESET researcher Facundo Muñoz, who analyzed Spellbinder and WizardNet. “Our research led us to discover a tool used by the attackers that is designed to perform adversary-in-the-middle attacks using IPv6 SLAAC spoofing to intercept and reply to packets in a network, allowing the attackers to redirect traffic and serve malicious updates to legitimate Chinese software,” explains Muñoz.

The final payload in the attack is a backdoor that we named WizardNet – a modular implant that connects to a remote controller to receive and execute .NET modules on the compromised machine. ESET researchers have focused on one of the latest cases, in 2024, in which the update of Tencent QQ software was hijacked. The malicious server that issues the update instructions is still active. This variant of WizardNet supports five commands, three of which allow it to execute .NET modules in memory, thus extending its functionality on the compromised system.

TheWizards and the Chinese company Dianke Network Security Technology (also known as UPSEC) – supplier of the DarkNights backdoor (also known as DarkNimbus), appear to be linked. According to NCSC UK, this malicious backdoor also has Tibetan and Uyghur communities among its primary targets. While TheWizards uses a different backdoor – the WizardNet, the hijacking server is configured to serve DarkNights to updating applications running on Android devices.

For a more detailed analysis and technical breakdown of TheWizards’ tools, check out the latest ESET Research blogpost “TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

About ESET

ESET® provides cutting-edge digital security to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown — securing businesses, critical infrastructure and individuals. Whether it’s endpoint, cloud or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit http://www.eset.com or follow our social media, podcasts and blogs.

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/e64e1152-5dee-4ed7-ad08-e0d87d089a16

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.
ShareTweet1ShareSendShare2
Previous Post

Aurora Mobile’s GPTBots.ai Integrates Alibaba’s Qwen3 Model to Continuously Deliver Cutting-Edge AI for Enterprises

Next Post

GPTBots Integrates Alibaba’s Qwen3 Model to Continuously Deliver Cutting-Edge AI for Enterprises

Related Posts

PROACTIS SA – Press Release (nomination R Archer and P Dennant)

Press Release Evolution of PROACTIS SA Governance PARIS, France – (1 May 2026) — Under the terms of the Board of Directors of the company PROACTIS SA (ISIN code: FR0004052561) held on the 14th April 2026, Mrs. Rebecca ARCHER has been appointed as Director in replacement of Mrs. Charlotte CARTER,...

Read moreDetails

BsStrategy Introduces AI-Driven Trading Environment for Structured Market Analysis

LOS ANGELES, May 02, 2026 (GLOBE NEWSWIRE) -- In response to the growing complexity and volume of financial market data, BsStrategy has introduced an AI-based quantitative trading environment designed to help users organize information and support more structured decision-making. Modern financial markets are characterized by constant streams of data, including...

Read moreDetails

NeuroSalt 2026 Analysis: Does the “Neuro Salt for Neuropathy” Really Work? Ingredients, Benefits & Concerns

New York City, NY, May 02, 2026 (GLOBE NEWSWIRE) -- A growing number of Americans suffering from chronic nerve pain, tingling, and numbness have begun searching for natural alternatives to prescription medications. Among the most searched terms in this space is “neuro salt for neuropathy” — a phrase that has gained...

Read moreDetails

SalesCloser Secures U.S. Patent for AI-Powered Conversational Workflow Technology

Vancouver, BC, May 01, 2026 (GLOBE NEWSWIRE) -- SalesCloser Technologies Ltd. (“SalesCloser” or the “Company”) (TSXV: SCAI) (FSE: MJ5), a pioneer in autonomous AI sales technology, today announced that the United States Patent and Trademark Office (the “USPTO”) has granted the Company U.S. Patent No. US12526253B1 for its "System and...

Read moreDetails

Nextech3D.ai Appoints New Independent Auditor

TORONTO, ON / ACCESS Newswire / May 1, 2026 / Nextech3D.ai Corp. (CSE:NTAR)(OTCQB:NEXCF)(FSE:1SS) ("Nextech3D.ai" or the "Company"), a technology company specializing in AI‑powered event technology and immersive digital solutions, today announced that Kreston GTA LLP ("Kreston GTA") has been appointed as the Company's new independent auditor, effective immediately. The appointment...

Read moreDetails

Carbonara Announces Run for U.S. Congress in Florida’s Redrawn 22nd District

Weston, FL, May 01, 2026 (GLOBE NEWSWIRE) -- Michael Carbonara today officially announced his candidacy for the United States House of Representatives in Florida's newly redrawn 22nd Congressional District, declaring his intent to challenge Debbie Wasserman Schultz under the Senate-passed congressional map adopted this week. Carbonara revealed his decision live...

Read moreDetails

Fort Lauderdale Commissioner John Herbst Endorses Michael Carbonara for Congress in FL-22

Fort Lauderdale, FL, May 01, 2026 (GLOBE NEWSWIRE) -- Michael Carbonara, Republican candidate for Congress, today announced the endorsement of Fort Lauderdale City Commissioner John C. Herbst. The endorsement adds another prominent South Florida elected official to the growing coalition of local leaders supporting Carbonara's bid to unseat Debbie Wasserman...

Read moreDetails

Trident Announces Receipt of Nasdaq Determination Letter and Intent to Request Hearing

SINGAPORE, May 01, 2026 (GLOBE NEWSWIRE) -- Trident Digital Tech Holdings Ltd (“Trident” or the “Company,” NASDAQ: TDTH), a leading catalyst for digital transformation in technology optimization services and Web 3.0 activation based in Singapore, today announced that it received a letter dated April 28, 2026 from the Listing Qualifications...

Read moreDetails

Acorn, Provider of Monitoring and Control Solutions for Generators, Cell Towers, Data Centers and other Critical Infrastructure, Hosts Q1 Earnings Call Thursday, May 7 at 11am ET

WILMINGTON, Del., May 01, 2026 (GLOBE NEWSWIRE) -- Acorn Energy, Inc. (Nasdaq: ACFN), provider of remote monitoring and control solutions for critical infrastructure assets, will report its first quarter 2026 results premarket on Thursday, May 7th and host a conference call at 11:00 a.m. ET. Jan Loeb, President & CEO,...

Read moreDetails

GuardHouse Camera Analyzed: All You Need To Know About the GuardHouse Watch Eye

New York City, NY, May 01, 2026 (GLOBE NEWSWIRE) -- You are well aware that a security camera is necessary for your home but might be surprised to learn that your neighbor's $1,200 system costs him more than $400 in subscription fees every 12 months, and the cameras are still...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • Top Cross-Chain DeFi Solutions to Watch by 2025

    87 shares
    Share 35 Tweet 22
  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    160 shares
    Share 64 Tweet 40
  • 74Software completes refinancing of its Term Loans and Revolving Credit Facility

    6 shares
    Share 2 Tweet 2
  • Top 5 Wallets for Seamless Multi-Chain Trading in 2025

    83 shares
    Share 33 Tweet 21
  • Discover 2025’s Top 5 Promising Low-Cap Crypto Gems

    99 shares
    Share 40 Tweet 25
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

There are currently no events.

Latest on Web3Wire

  • Next-Generation Sound Arrives: Kiwi Ears Launches Halcyon Tribrid IEM on Kickstarter
  • PROACTIS SA – Press Release (nomination R Archer and P Dennant)
  • BsStrategy Introduces AI-Driven Trading Environment for Structured Market Analysis
  • NeuroSalt 2026 Analysis: Does the “Neuro Salt for Neuropathy” Really Work? Ingredients, Benefits & Concerns
  • SalesCloser Secures U.S. Patent for AI-Powered Conversational Workflow Technology

RSS Latest on Block3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age

RSS Latest on Meta3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Founder’s Note
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Web3Wire Whitepaper | Tokenomics

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!

The Klyrox Protocol | The Algorithmic Monographs

Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News

Media Portfolio: Block3Wire | Meta3Wire

  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.