IPv6 networking function struck by pirates to divert the software updates


  • The Chinese threat actor Thewizards has observed a Slaac attack since 2022
  • The attack offers contaminated software updates
  • Most of the victims are in China, Hong Kong, Philippines and Water

A threat actor called Thewizards has launched SLAAC usurpation attacks to target organizations, revealed that ESET cybersecurity researchers have revealed that the group is aligned with the Chinese government.

In the campaign, the attackers would use a tool called Spellbinder to send messages of false router advertising (RA) to their targets.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top