TheWizard is an advanced persistent threat cluster associated with China-aligned intrusion activity. It has been linked to use of the WizardNet backdoor and to infrastructure overlaps involving the HOLODONUT backdoor. Reporting also associates TheWizard with deployment of the DarkNimbus backdoor, which has been described as developed by Earth Minotaur. The actor appears in attribution chains connecting broader intrusion sets through shared command-and-control infrastructure and malware-family relationships. Observed tradecraft tied to TheWizard includes use of modular backdoors for post-compromise access and control, with overlaps to campaigns that abused living-off-the-land binaries and script-based delivery frameworks to execute payloads across multiple environments. Through its association with WizardNet and HOLODONUT-linked activity, TheWizard is connected to operations emphasizing stealthy backdoor deployment, persistent access, and follow-on post-exploitation capability. Available information supports characterization of the actor as part of China-aligned espionage activity, but specific victim sectors, countries targeted, and a fuller independent operational profile for TheWizard remain limited in the available evidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced due to shared C2 infrastructure (mkdmcdn.com) with HOLODONUT samples; described as also deploying the DarkNimbus backdoor.
APT referenced as a likely linkage point for the newly observed HoloDonut backdoor via similarity/association with WizardNet.
China-aligned APT referenced due to infrastructure overlap: HOLODONUT samples in SHADOW-VOID-044 used a C2 also used by TheWizard. TheWizard is also noted as having used DarkNimbus (developed by Earth Minotaur).
Assessed linked (via HOLODONUT and WizardNet ties) to PeckBirdy-enabled activity delivering .NET backdoors and related tooling in China-aligned operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.