WizardNet is a modular Windows backdoor associated with the China-aligned threat actor TheWizards and deployed through adversary-in-the-middle operations conducted with the Spellbinder framework. Public reporting places its use since at least 2022, with victims including individuals, gambling companies, and other organizations in mainland China, Hong Kong, the Philippines, Cambodia, and the United Arab Emirates. WizardNet has also been linked through infrastructure and tooling overlaps to broader China-nexus activity involving DarkNimbus and DKnife, suggesting a shared operational or supplier ecosystem.
The malware is typically delivered after Spellbinder hijacks legitimate software update traffic by abusing IPv6 SLAAC and ICMPv6 router advertisement spoofing to redirect DNS queries and update requests toward attacker-controlled infrastructure. In observed intrusions, a malicious downloader or trojanized update component retrieves an encrypted blob whose shellcode loads WizardNet in memory. The intrusion chain has included abuse of a legitimate AVG component for DLL sideloading, use of WinPcap to support traffic interception, and in-memory execution of the final payload.
WizardNet is a .NET-based modular implant that connects to a remote controller and receives additional .NET modules for execution on the compromised host. Reported functionality includes downloading and loading modules, executing attacker-supplied code in memory, maintaining host-specific identifiers, and communicating with command-and-control over encrypted channels using a derived session key. Defense-evasion behavior includes patching AMSI and ETW to reduce visibility, and the malware can read shellcode from local storage and inject it into other processes for post-compromise execution. These characteristics make WizardNet a flexible post-exploitation platform suited to long-term espionage and follow-on operations on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We also discovered that SHADOW-VOID-044 used the HOLODONUT backdoor, which is likely linked to another backdoor, WizardNet, previously reported being used by an APT group called TheWizard.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
“The downloader and shellcode… dynamically resolve API addresses.”
“The shellcode obtained by the downloader contains WizardNet in encrypted form.”
“WizardNet… attempts to inject [shellcode] into a new process of explorer.exe or %ProgramFiles%\Windows Photo Viewer\ImagingDevices.exe.”
“WizardNet uses the QueueUserApc API to execute injected code.”
“Depending on its configuration, WizardNet can then create a TCP or UDP socket to communicate with its C&C server…”
"...redirecting the traffic of legitimate Chinese software so that it downloads malicious updates from a server controlled by the attackers"
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously reported backdoor mentioned as likely linked to HOLODONUT through infrastructure overlap and reporting on TheWizard.
Backdoor referenced as linked to the DKnife toolchain/campaign; specific capabilities not described in the provided content.
Malware/tooling linked by shared infrastructure and similar update-hijacking tradecraft to DKnife; previously associated (in this content) with campaigns impacting the Philippines, Cambodia, and the UAE.
Backdoor/framework mentioned as overlapping in infrastructure/TTPs with DKnife activity and used in related regional operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.