Tag: outer Advertisement (RA)

Hackers abuse IPv6 networking feature to hijack software updates
News

Hackers abuse IPv6 networking feature to hijack software updates

An IPv6 networking capability is abused by the China-aligned APT threat actor "TheWizards" to initiate adversary-in-the-middle (AitM) assaults that use software upgrades to infect Windows with malware. ESET claims that the gang has been active since at least 2022 and has targeted organizations in China, Hong Kong, the Philippines, Cambodia, and the United Arab Emirates. Individuals, gambling firms, and other organizations are among the victims. ESET's "Spellbinder" is a proprietary program that exploits the IPv6 Stateless Address Autoconfiguration (SLAAC) feature to carry out SLACC attacks. Without requiring a DHCP server, devices can autonomously create their own IP addresses and default gateway thanks to SLAAC, a component of the IPv6 networking protocol. Rather, it uses Router...