Source |
GB Hacker |
Identifiant |
8669989 |
Date de publication |
2025-04-30 13:43:57 (vue: 2025-04-30 15:12:47) |
Titre |
TheWizards Deploy \\ 'Spellbinder Hacking Tool \\' for Global Adversary in the Middle Attack TheWizards Deploy \\'Spellbinder Hacking Tool\\' for Global Adversary-in-the-Middle Attack |
Texte |
Les chercheurs ESET ont découvert des techniques d'attaque sophistiquées employées par un acteur de menace aligné sur la Chine surnommé «Thewizards», qui cible activement des entités à travers l'Asie et le Moyen-Orient depuis 2022. Le groupe utilise un outil de mouvement laté Mises à jour […]
ESET researchers have uncovered sophisticated attack techniques employed by a China-aligned threat actor dubbed “TheWizards,” which has been actively targeting entities across Asia and the Middle East since 2022. The group employs a custom lateral movement tool called Spellbinder that performs adversary-in-the-middle (AitM) attacks using IPv6 SLAAC spoofing, allowing attackers to redirect legitimate software updates […]
|
Notes |
★★
|
Envoyé |
Oui |
Condensat |
“thewizards 2022 across actively actor adversary aitm aligned allowing asia attack attackers attacks been called china custom deploy dubbed east employed employs entities eset global group hacking has have ipv6 lateral legitimate middle movement performs redirect researchers since slaac software sophisticated spellbinder spoofing targeting techniques thewizards threat tool uncovered updates using which |
Tags |
Tool
Threat
|
Stories |
|
Move |
|