WizardNet is a modular Windows backdoor associated with the China-aligned threat actor TheWizards. It is deployed through adversary-in-the-middle operations conducted with the Spellbinder framework, which abuses IPv6 Stateless Address Autoconfiguration and ICMPv6 Router Advertisement spoofing to redirect software update traffic from legitimate Chinese applications to attacker-controlled infrastructure. Observed delivery chains include hijacked updates for software such as Tencent QQ and earlier activity involving Sogou Pinyin, where a malicious downloader or dropper ultimately loads WizardNet in memory.
WizardNet is designed as a modular implant that connects to a remote controller and receives .NET modules for execution on the compromised host. Reported behavior includes in-memory loading through a downloader that initializes the .NET runtime, decrypts payloads, and patches AMSI and ETW to reduce visibility. The malware communicates using encrypted TCP or UDP channels and maintains host-specific identifiers derived from system attributes. It has also been observed reading shellcode from local storage and attempting process injection into legitimate Windows processes.
The malware has been linked to campaigns targeting individuals, gambling-related organizations, and other entities in the Philippines, Cambodia, the United Arab Emirates, mainland China, Hong Kong, and potentially other regions. Infrastructure and tradecraft overlaps have also linked WizardNet activity to broader China-nexus adversary-in-the-middle ecosystems involving Spellbinder, DarkNights or DarkNimbus, and DKnife. Security reporting has additionally noted likely ties between WizardNet and the HOLODONUT backdoor, suggesting shared development or operational lineage within related espionage campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“The downloader then acts as a conduit to drop a modular backdoor codenamed WizardNet.”
21 distinct techniques documented for this family, organized by ATT&CK tactic.
“The downloader and shellcode… dynamically resolve API addresses.”
“The shellcode obtained by the downloader contains WizardNet in encrypted form.”
“WizardNet… attempts to inject [shellcode] into a new process of explorer.exe or %ProgramFiles%\Windows Photo Viewer\ImagingDevices.exe.”
“WizardNet uses the QueueUserApc API to execute injected code.”
“Depending on its configuration, WizardNet can then create a TCP or UDP socket to communicate with its C&C server…”
"...redirecting the traffic of legitimate Chinese software so that it downloads malicious updates from a server controlled by the attackers"
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor referenced as linked to the DKnife toolchain/campaign; specific capabilities not described in the provided content.
Malware/tooling linked by shared infrastructure and similar update-hijacking tradecraft to DKnife; previously associated (in this content) with campaigns impacting the Philippines, Cambodia, and the UAE.
Backdoor/framework mentioned as overlapping in infrastructure/TTPs with DKnife activity and used in related regional operations.
Modular backdoor referenced as delivered in AitM-style campaigns; linked in the text to tooling lineage shared with other AitM frameworks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.