Spellbinder, a lateral movement tool that can support adversary-in-the-middle (AitM) operations, has been connected to TheWizards, an advanced persistent threat (APT) group with ties to China.
In a report shared with The Hacker News, ESET researcher Facundo Muñoz claimed that Spellbinder allows adversary-in-the-middle (AitM) attacks to move laterally in the compromised network by using IPv6 stateless address autoconfiguration (SLAAC) spoofing to intercept packets and reroute the traffic of legitimate Chinese software so that it downloads malicious updates from a server under the attackers’ control.
The exploit opens the door for a malicious downloader, which is distributed via taking over the Sogou Pinyin software update system. After then, the downloader serves as a conduit for the installation of a modular backdoor known as WizardNet read more about Chinese Hackers Abuse IPv6 SLAAC for AitM Attacks via Spellbinder Lateral Movement Tool.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
