Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors TheWizards

Also known as: UPSEC, APT28, APT34, Earth Preta, Stately Taurus, tracked as, the Ithryn Luin, Haimenar, Palacendo, Morinehtar, DeadCatx3, PCPcat, PersyPCP, ShellForce, Wizards, mostly of fantasy, science-fiction games, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, DarkNimbus, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257, PUSHCHA, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, Smoke Sandstorm, TA455, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, Imperial Kitten, TA456, Yellow Liderc, Desert Falcon, Arid Viper, Bearded Barbie

Description

TheWizards has been identified by ESET researchers as a sophisticated threat actor aligned with state interests in China. Their core capabilities revolve around redirecting legitimate software update traffic through an IPv6‑based Adversary‑in‑the‑Middle tool named Spellbinder, which exploits SLAAC spoofing to establish command-and-control (C2) channels without raising network alarms. Upon compromising a host, the attackers deploy a custom backdoor dubbed WizardNet that is capable of installing additional payloads, executing shellcode stored in the registry, and leveraging dynamic API resolution to evade static analysis. In addition to the Spellbinder/WizardNet chain, TheWizards routinely uses the Windows packet capture library WinPcap as a covert persistence utility. They also maintain malicious domains such as hao.com and ssl‑dns.com for phishing and hosting exploitation modules, while deploying widely known exploits for Zero Logon (CVE‑2020‑1472) and EternalBlue (MS17‑010) to bypass authentication and establish footholds in unpatched systems. The group’s operations span a wide array of sectors—including government, defense, financial services, telecommunications, health care, manufacturing, energy, media, critical infrastructure, aerospace, and more—across countries such as China, the United States, Russia, Ukraine, UAE, Israel, Vietnam, Pakistan, Iran, Belarus, Japan, India, Turkey, Germany, South Korea, and others. Their tactics blend classic espionage with advanced operational security measures, showcasing a blend of technical skill and strategic targeting. While their overall strategic intent remains primarily intelligence gathering and data exfiltration, TheWizards demonstrates a willingness to leverage high‑impact vulnerabilities and public delivery mechanisms, indicating an aggressive posture that could evolve into destructive campaigns if new opportunities arise.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Telecommunications
Education
Healthcare
Non profit
Manufacturing
Energy
Media
Critical infrastructure
Think tank
Aerospace
Pharmaceutical
Aviation
Hospitality
Transportation
Retail
Chemical
Maritime
Legal services
Information technology
Mining
Gaming
Nuclear
Entertainment
Utilities
Oil gas
Construction

Targeted Countries / Regions

CN
US
RU
UA
AE
IL
VN
PK
IR
BY
JP
IN
TW
GB
KR
SA
PL
AU
TR
DE
LB
KZ
SG
IT
FR
MX
ES
CA
IQ
RO
NG
KP
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 22 hours ago

Executive Summary

TheWizards is a China‑aligned APT actor that leverages an IPv6 adversary‑in‑the‑middle tool called Spellbinder to hijack legitimate software update channels and deploy its signature backdoor WizardNet. It combines classic espionage TTPs—phishing, credential theft, exploitation of Zero Logon and EternalBlue—with modern obfuscation techniques such as dynamic API resolution and registry‑based shellcode storage. The group operates across a wide geographic range in Asia, the Middle East, and Europe, targeting both government and commercial sectors.

Goals & Targeting

TheWizards’ primary objective is long‑term espionage against governmental, defense, and critical infrastructure targets across Asia, the Middle East, and Europe. By hijacking legitimate update channels they aim to establish a discreet foothold, enabling sustained data collection while keeping the attack surface minimal. Their broad sector coverage—including commercial utilities, healthcare systems, and manufacturing environments—signals an intent to harvest both classified policy documents and proprietary industrial information that could be leveraged for strategic advantage by allied actors.

Enhanced Description

Key Capabilities

  • Adversary‑in‑the‑Middle via Spellbinder with SLAAC spoofing
  • Deployment of WizardNet backdoor
  • Registration of malicious domains (hao.com, ssl-dns.com, mkdmcdn.com) for C2 and update hosting
  • Installation of WinPcap to facilitate network traffic capture and persistence
  • Execution of commands through cmd.exe to download and run tools
  • Storage of encrypted shellcode in the Windows registry
  • Dynamic API resolution obfuscation techniques
  • Exploitation of Zero Logon (CVE‑2020‑1472) vulnerability
  • Exploitation of EternalBlue (MS17‑010) for lateral movement
  • Phishing campaigns targeting academic and defense organizations
  • Credential theft from password stores

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Privilege Escalation
Discovery
Credential Access
Exfiltration

ATT&CK Techniques

T1557
T1027.009
T1543
T1133
T1547
T1587.001
T1573.001
T1082
T1071
T1106
T1005
T1555
T1567
T1583.001
T1659
T1055
T1480.002
T1611
T1560
T1112
T1583.004
T1087
T1059
T1055.004
T1074
T1041
T1210
T1048
T1588.002
T1027.014
T1685
T1095
T1197
T1518.001
T1585
T1059.003
T1136
T1105
T1027.007
T1124

Software / Tooling

Spellbinder
WizardNet
DarkNimbus
Zerologon exploitation module
EternalBlue exploitation module
WinPcap
cmd.exe

Campaigns & Victims

TheWizards operates in a pattern that blends low‑visibility delivery with rapid exploitation of widely known Windows vulnerabilities. Their campaigns typically begin with phishing or compromised supply chains, followed by deployment of Spellbinder to hijack legitimate software update streams. The group then installs WizardNet and supplementary tools such as DarkNimbus and WinPcap to maintain persistence and facilitate data collection. Over time, they stage data in the registry or staging directories before exfiltrating it via controlled C2 channels using TLS‑based protocols. They have been active against a wide range of victim types—from government ministries to private utilities—and are known for shifting domains frequently to avoid detection.

IOC Patterns

  • Malicious domain registrations (hao.com, ssl-dns.com, mkdmcdn.com)
  • Registry entries containing encrypted shellcode
  • Dynamic API resolution calls for obfuscation
  • Use of cmd.exe for downloading and executing remote tools
  • Installation of WinPcap on endpoints
  • Vulnerability exploitation signatures for Zero Logon and EternalBlue
  • Phishing email patterns targeting academic and defense organizations

Recommended Actions

  • Block outbound traffic to known malicious domains such as hao.com, ssl‑dns.com, mkdmcdn.com, and any newly registered domains exhibiting similar name patterns.
  • Deploy endpoint detection that monitors the execution of Spellbinder and WizardNet binaries; flag anomalous usage of cmd.exe for downloading files.
  • Implement strict controls on WinPcap installation via whitelisting or application control policies.
  • Scan registries for unusual encrypted payload entries and monitor for unauthorized registry modifications.
  • Enforce MFA and strengthen account permissions to limit privilege escalation opportunities. Patch critical Windows vulnerabilities promptly, with a focus on Zero Logon (CVE‑2020‑1472) and Exploit MS17‑010; ensure all systems run the latest security updates. Enhance email filtering and user training to reduce successful phishing attacks against high‑value targets.
  • suggested_tags
  • ["APT","China-APT","TheWizards","Spellbinder","WizardNet","DarkNimbus","SLAAC Spoofing","Zero Logon exploitation","EternalBlue exploitation","Adversary‑in‑the‑Middle"]
  • confidence_assessment

ATT&CK Techniques

Initial Access
1 technique
Lateral Movement
1 technique
Privilege Escalation
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-1 Hash 6 Domain 7 Filename 5 MD5 Hash 2

References

  1. www.eset.com — Cited by web research for: APT28
  2. www.welivesecurity.com — Cited by web research for: T1112
  3. attack.mitre.org — Cited by web research for: T1557
  4. attack.mitre.org — Cited by web research for: Akira
  5. www.eset.com — Cited by web research for: UK

Intel Summary

40

Techniques

48

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

APT
Supply Chain Attack
Backdoor / C2

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.