Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
1 résultat taggé TheWizards  ✕
TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks https://www.welivesecurity.com/en/eset-research/thewizards-apt-group-slaac-spoofing-adversary-in-the-middle-attacks/
01/05/2025 13:31:03
QRCode
archive.org
thumbnail

ESET researchers publish an analysis of Spellbinder, a lateral movement tool used to perform adversary-in-the-middle attacks.<<

  • We discovered a malicious downloader being deployed, by legitimate Chinese software update mechanisms, onto victims’ machines.
  • The downloader seeks to deploy a modular backdoor that we have named WizardNet.
  • We analyzed Spellbinder: the tool the attackers use to conduct local adversary-in-the-middle attacks and to redirect traffic to an attacker-controlled server to deliver the group’s signature backdoor WizardNet.
  • We provide details abouts links between TheWizards and the Chinese company Dianke Network Security Technology, also known as UPSEC.
welivesecurity EN 2025 TheWizards APT SLAAC UPSEC spoofing adversary-in-the-middle lateral-movement
4290 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio