Skip to main content
Mallory
Back to malware
MalwareUsed by 2 actors

Spellbinder

Spellbinder is a lateral movement and adversary-in-the-middle (AitM) framework used by the China-aligned espionage group TheWizards. ESET reported the tool has been used since at least 2022 to move laterally inside compromised networks by abusing IPv6 stateless address autoconfiguration (SLAAC) and ICMPv6 Router Advertisement spoofing. Spellbinder sends multicast Router Advertisements to make victim hosts use the attacker-controlled system as the default gateway, then intercepts packets and redirects traffic.

Its primary observed use is hijacking legitimate software update traffic for Chinese applications and redirecting victims to attacker-controlled infrastructure serving malicious updates. Spellbinder uses WinPcap for packet capture and packet crafting, can enumerate and select network adapters, and can respond to DNS queries, ICMPv6 Router Solicitations, Neighbor Advertisements, and DHCPv6 Solicit/Information-request traffic. It monitors DNS requests for a hardcoded set of targeted Chinese-platform domains, including services associated with Tencent, Baidu, Xunlei, Youku, iQIYI, Kingsoft, Mango TV, Funshion, Youdao, Xiaomi/MIUI, PPLive, Meitu, Qihoo 360, and Baofeng. When a targeted domain is queried, it forges DNS responses pointing to attacker-controlled IPs. Reported hijack IPs include 43.155.116[.]7 in 2022 and 43.155.62[.]54 in 2024; one observed 2024 case redirected update.browser.qq.com to 43.155.62[.]54 to hijack Tencent QQ updates.

ESET described deployment after initial access via a ZIP archive containing AVGApplicationFrameHost.exe, wsc.dll, log.dat, and winpcap.exe, extracted under %PROGRAMFILES%\AVG Technologies. A legitimate AVG component is abused for DLL side-loading: AVGApplicationFrameHost.exe loads wsc.dll, which reads shellcode from log.dat and executes it in memory, ultimately loading Spellbinder. In observed campaigns, Spellbinder-enabled traffic hijacking delivered a malicious downloader through trojanized software updates. In a Tencent QQ case, the attacker server returned JSON update instructions causing QQ.exe to download minibrowser11_rpl.zip, which deployed minibrowser_shell.dll; that DLL executed only when the process name contained "QQ" and then fetched an encrypted blob that loaded the WizardNet backdoor in memory.

Spellbinder is directly linked to delivery of WizardNet, a modular Windows backdoor used by TheWizards, and reporting also notes infrastructure configured to serve DarkNights/DarkNimbus to Android applications. ESET telemetry linked TheWizards and Spellbinder-related activity to targets including individuals, gambling companies, and other entities in the Philippines, Cambodia, the United Arab Emirates, mainland China, and Hong Kong. Reported infrastructure and indicators associated with Spellbinder-enabled malicious updates include 43.155.116[.]7, 43.155.62[.]54, and domains such as hao[.]com and vv.ssl-dns[.]com.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
TheWizards

“Spellbinder enables adversary-in-the-middle (AitM) attacks, through IPv6 stateless address autoconfiguration (SLAAC) spoofing, to move laterally in the compromised network, intercepting packets and redirecting the traffic…”

via the hacker newsthehackernews.com
china_nexus_apt_groups

"...in conjunction with other modular frameworks such as Spellbinder and WizardNet..."

via rescana blogrescana.com
MITRE ATT&CK

Techniques & procedures

13 distinct techniques documented for this family, organized by ATT&CK tactic.

T1583.001DomainsEvidence1

“TheWizards has registered the domains hao[.]com, ssl-dns[.]com, and mkdmcdn[.]com.”

T1583.004ServerEvidence1

“TheWizards acquired servers for hosting tools, C&C, and to serve malicious updates.”

T1587.001MalwareEvidence1

“TheWizards uses custom malware such as the WizardNet backdoor and Spellbinder.”

T1588.002ToolEvidence1

“TheWizards installs WinPcap on compromised machines; it is required by Spellbinder.”

Initial Access

2 techniques
T1195.002Compromise Software Supply ChainEvidence2

"...hijacking the software update mechanism associated with Sogou Pinyin..."; "...hijack the software update process for Tencent QQ... to serve a trojanized version"

T1659Content InjectionEvidence1

“Spellbinder… redirect traffic and serve malicious updates… Spellbinder tool intercepts the DNS query for that domain name and issues a DNS answer with the IP address of an attacker-controlled server used for hijacking…”

Execution

2 techniques
T1059.001PowerShellEvidence1
TacticExecution

"The DLL file subsequently reads shellcode from 'log.dat' and executes it in memory"

T1574.001DLLEvidence1

"...run 'AVGApplicationFrameHost.exe,' the latter of which is abused to sideload the DLL."

Stealth

2 techniques
T1027.014Polymorphic CodeEvidence1
TacticStealth

“The file log.dat contains polymorphic decryption code that loads the Spellbinder tool into memory.”

T1574.001DLLEvidence1

"...run 'AVGApplicationFrameHost.exe,' the latter of which is abused to sideload the DLL."

Credential Access

2 techniques
T1040Network SniffingEvidence1

"Spellbinder uses the WinPcap library to capture packets"

T1557Adversary-in-the-MiddleEvidence1

"abuse IPv6 SLAAC for AitM attacks via Spellbinder"

Discovery

1 technique
T1040Network SniffingEvidence1

"Spellbinder uses the WinPcap library to capture packets"

Collection

1 technique
T1557Adversary-in-the-MiddleEvidence1

"abuse IPv6 SLAAC for AitM attacks via Spellbinder"

T1105Ingress Tool TransferEvidence1

"...redirecting the traffic of legitimate Chinese software so that it downloads malicious updates from a server controlled by the attackers"

T1659Content InjectionEvidence1

“Spellbinder… redirect traffic and serve malicious updates… Spellbinder tool intercepts the DNS query for that domain name and issues a DNS answer with the IP address of an attacker-controlled server used for hijacking…”

Impact

1 technique
T1565.001Stored Data ManipulationEvidence1
TacticImpact

"...intercepting the DNS query for the software update domain ... and issuing a DNS response with the IP address of an attacker-controlled server"

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app1 year ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping13

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.