In this blogpost, ESET researchers provide an analysis of Spellbinder, a lateral movement tool for performing adversary-in-the-middle attacks, used by the China-aligned threat actor that we have named ...
RSAC CONFERENCE 2025 – San Francisco – A Chinese advanced persistent threat (APT) known as TheWizards is conjuring "Spellbinder," a lateral movement tool that enables a unique adversary-in-the-middle ...
A China-aligned APT threat actor named "TheWizards" abuses an IPv6 networking feature to launch adversary-in-the-middle (AitM) attacks that hijack software updates to install Windows malware.