Researchers detailed multiple China-aligned intrusion sets using modular tooling to compromise targets across Windows, web, and mobile environments. ESET said TheWizards used a tool called Spellbinder to abuse IPv6 SLAAC by sending rogue ICMPv6 Router Advertisements, positioning the attackers as the default gateway for adversary-in-the-middle operations. The group then intercepted DNS requests for Chinese software vendors and redirected update traffic so legitimate applications such as Tencent QQ and previously Sogou Pinyin fetched malicious payloads instead of real updates. The resulting infection chain used a downloader DLL, an encrypted blob, and in-memory loading of the WizardNet backdoor, which patched AMSI and ETW, supported modular execution, and injected shellcode into other processes while maintaining encrypted command-and-control.
Separate reporting described broader China-linked operations using flexible malware delivery and post-compromise frameworks. Trend Micro tied Earth Minotaur to the MOONSHINE Exploit Kit and the DarkNimbus Android backdoor, while TrendAI documented PeckBirdy, a JScript-based framework used since 2023 across browsers, MSHTA, WScript, Classic ASP, Node.js, and .NET ScriptControl for watering-hole attacks, credential theft, lateral movement, reverse shells, and persistent backdoor access. PeckBirdy was observed in campaigns against Chinese gambling sites, Asian government entities, and private organizations, alongside modular backdoors HOLODONUT and MKDOOR. The reporting also noted infrastructure and tooling overlaps linking some of these activities to UNC3569, Earth Baxia, and supplier UPSEC, underscoring an ecosystem of China-aligned operators reusing shared malware, hijacking infrastructure, and fake software-update lures.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
TrendAI published research on the previously unseen JScript-based PeckBirdy command-and-control framework and the SHADOW-VOID-044 and SHADOW-EARTH-045 campaigns that used it. The report also linked SHADOW-VOID-044 to UNC3569 with moderate-to-high confidence and SHADOW-EARTH-045 to Earth Baxia with low confidence.
ESET published research detailing the China-aligned threat actor TheWizards, its IPv6 SLAAC-spoofing adversary-in-the-middle tool Spellbinder, and the WizardNet backdoor. The report also described targeting across the Philippines, Cambodia, the UAE, mainland China, and Hong Kong, and noted links to Sichuan Dianke Network Security Technology (UPSEC).
During July 2024, researchers observed the SHADOW-EARTH-045 campaign using PeckBirdy against Asian government entities and private organizations. Activity included injecting PeckBirdy links into government websites and using MSHTA-executed PeckBirdy for lateral movement inside a private organization.
In a 2024 incident, TheWizards intercepted DNS requests for update.browser.qq.com and redirected them to 43.155.62[.]54 to hijack Tencent QQ updates. The attacker server returned JSON instructions that caused QQ.exe to download minibrowser11_rpl.zip, leading to execution of the malicious minibrowser_shell.dll and deployment of WizardNet.
ESET said TheWizards remained active through 2023 and 2024, with newer versions of its tooling observed during that period. This indicates continued development and operational use after the group's 2022 activity.
Researchers observed PeckBirdy campaigns beginning in 2023. The framework was used in operations targeting the Chinese gambling industry as well as Asian government entities and private organizations.
ESET reported that in 2022 it observed Sogou Pinyin downloading a suspicious DLL that acted as a dropper for a downloader used in TheWizards intrusions. The same year, Spellbinder used the attacker IP 43.155.116[.]7 for forged DNS responses in its hijacking activity.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
trendaisecurity.com
Open sourcewelivesecurity.com
Open sourcetrendmicro.com
Open sourcevirusbulletin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.