TheWizards
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:12:16
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:ph country_code:kh country_code:ae country_code:cn country_code:hk
Context
TheWizards is a China-aligned APT group that employs the Spellbinder tool for adversary-in-the-middle attacks, utilizing IPv6 SLAAC spoofing to redirect legitimate software updates to malicious servers. They have developed the WizardNet backdoor for Windows and serve DarkNights to Android applications, indicating a connection to Dianke Network Security Technology. The group targets individuals and companies in the Philippines, Cambodia, the UAE, mainland China, and Hong Kong. ESET has observed their infrastructure and tools, including the acquisition of servers for hosting C&C and malicious updates.
Reports & references
- ESET — Nspx30 Sophisticated Aitm Enabled Implant Evolving Since 2005 (report)
- ESET — Thewizards Apt Group Slaac Spoofing Adversary In The Middle Attacks (report)