Also known as: UPSEC, APT28, APT34, Earth Preta, Stately Taurus, tracked as, the Ithryn Luin, Haimenar, Palacendo, Morinehtar, DeadCatx3, PCPcat, PersyPCP, ShellForce, Wizards, mostly of fantasy, science-fiction games, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, DarkNimbus, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257, PUSHCHA, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, Smoke Sandstorm, TA455, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, Imperial Kitten, TA456, Yellow Liderc, Desert Falcon, Arid Viper, Bearded Barbie
TheWizards has been identified by ESET researchers as a sophisticated threat actor aligned with state interests in China. Their core capabilities revolve around redirecting legitimate software update traffic through an IPv6‑based Adversary‑in‑the‑Middle tool named Spellbinder, which exploits SLAAC spoofing to establish command-and-control (C2) channels without raising network alarms. Upon compromising a host, the attackers deploy a custom backdoor dubbed WizardNet that is capable of installing additional payloads, executing shellcode stored in the registry, and leveraging dynamic API resolution to evade static analysis. In addition to the Spellbinder/WizardNet chain, TheWizards routinely uses the Windows packet capture library WinPcap as a covert persistence utility. They also maintain malicious domains such as hao.com and ssl‑dns.com for phishing and hosting exploitation modules, while deploying widely known exploits for Zero Logon (CVE‑2020‑1472) and EternalBlue (MS17‑010) to bypass authentication and establish footholds in unpatched systems. The group’s operations span a wide array of sectors—including government, defense, financial services, telecommunications, health care, manufacturing, energy, media, critical infrastructure, aerospace, and more—across countries such as China, the United States, Russia, Ukraine, UAE, Israel, Vietnam, Pakistan, Iran, Belarus, Japan, India, Turkey, Germany, South Korea, and others. Their tactics blend classic espionage with advanced operational security measures, showcasing a blend of technical skill and strategic targeting. While their overall strategic intent remains primarily intelligence gathering and data exfiltration, TheWizards demonstrates a willingness to leverage high‑impact vulnerabilities and public delivery mechanisms, indicating an aggressive posture that could evolve into destructive campaigns if new opportunities arise.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
TheWizards is a China‑aligned APT actor that leverages an IPv6 adversary‑in‑the‑middle tool called Spellbinder to hijack legitimate software update channels and deploy its signature backdoor WizardNet. It combines classic espionage TTPs—phishing, credential theft, exploitation of Zero Logon and EternalBlue—with modern obfuscation techniques such as dynamic API resolution and registry‑based shellcode storage. The group operates across a wide geographic range in Asia, the Middle East, and Europe, targeting both government and commercial sectors.
Goals & Targeting
TheWizards’ primary objective is long‑term espionage against governmental, defense, and critical infrastructure targets across Asia, the Middle East, and Europe. By hijacking legitimate update channels they aim to establish a discreet foothold, enabling sustained data collection while keeping the attack surface minimal. Their broad sector coverage—including commercial utilities, healthcare systems, and manufacturing environments—signals an intent to harvest both classified policy documents and proprietary industrial information that could be leveraged for strategic advantage by allied actors.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
TheWizards operates in a pattern that blends low‑visibility delivery with rapid exploitation of widely known Windows vulnerabilities. Their campaigns typically begin with phishing or compromised supply chains, followed by deployment of Spellbinder to hijack legitimate software update streams. The group then installs WizardNet and supplementary tools such as DarkNimbus and WinPcap to maintain persistence and facilitate data collection. Over time, they stage data in the registry or staging directories before exfiltrating it via controlled C2 channels using TLS‑based protocols. They have been active against a wide range of victim types—from government ministries to private utilities—and are known for shifting domains frequently to avoid detection.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
40
Techniques
48
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics