Spellbinder is an adversary-in-the-middle lateral movement tool used by the China-aligned espionage group TheWizards. It abuses IPv6 Stateless Address Autoconfiguration and ICMPv6 Router Advertisement spoofing to position an attacker-controlled host as the default gateway for nearby systems on a compromised network. Once in that position, it intercepts and redirects traffic, particularly DNS lookups and software update requests, enabling the operators to hijack legitimate update mechanisms and deliver follow-on malware.
The tool has been observed on Windows systems and is loaded in memory after deployment through DLL sideloading involving a legitimate application component. It uses packet-capture functionality to enumerate interfaces, monitor network changes, capture traffic, and craft forged responses on the local network. Reported behaviors include sending repeated multicast Router Advertisements, replying to DNS queries for a hardcoded set of targeted software and service domains, and handling other local network protocol traffic associated with IPv6 neighbor discovery and configuration. This allows Spellbinder to rapidly affect multiple hosts on the same segment with minimal visible disruption.
Spellbinder has been used to redirect update traffic for widely used Chinese software so victims retrieve malicious updates from attacker-controlled infrastructure. In observed operations, this traffic hijacking delivered a downloader that ultimately loaded the WizardNet backdoor in memory. The broader activity has targeted individuals, gambling companies, and other entities in mainland China, Hong Kong, the Philippines, Cambodia, and the United Arab Emirates. Spellbinder is part of a wider ecosystem of China-aligned adversary-in-the-middle tooling linked to software-update hijacking and downstream deployment of modular espionage implants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Spellbinder: lateral movement tool that performs AitM via IPv6 Stateless Address Autoconfiguration (SLAAC) spoofing attack.
“Spellbinder enables adversary-in-the-middle (AitM) attacks, through IPv6 stateless address autoconfiguration (SLAAC) spoofing, to move laterally in the compromised network, intercepting packets and redirecting the traffic…”
14 distinct techniques documented for this family, organized by ATT&CK tactic.
“TheWizards has registered the domains hao[.]com, ssl-dns[.]com, and mkdmcdn[.]com.”
“TheWizards acquired servers for hosting tools, C&C, and to serve malicious updates.”
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Tool enabling adversary-in-the-middle attacks via IPv6 SLAAC spoofing to move laterally and intercept traffic.
A framework referenced as associated with the same ecosystem/campaign as DKnife; specific functionality not described in the provided content.
Traffic-hijacking capability/campaign referenced as a delivery mechanism for WizardNet; described here as conducting traffic-hijacking attacks that align with DKnife-style update hijacking.
Modular framework referenced as used alongside DKnife in the same China-nexus toolchain ecosystem to support persistence/flexible access.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.