TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks

TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks

In this blogpost, ESET researchers provide an analysis of Spellbinder, a lateral movement tool for performing adversary-in-the-middle attacks, used by the China-aligned threat actor that we have named TheWizards. Spellbinder enables adversary-in-the-middle (AitM) attacks, through IPv6 stateless address autoconfiguration (SLAAC) spoofing, to move laterally in the compromised network, intercepting packets and redirecting the traffic of…

Read More
The Anatomy of a Skype Group Chat Scam: How Bots Manipulate Victims into Crypto Fraud • AI Blog

The Anatomy of a Skype Group Chat Scam: How Bots Manipulate Victims into Crypto Fraud • AI Blog

Shouldn’t Microsoft then at least be held legally and financially liable for damages caused by such scams on their platform? Should Microsoft Be Held Legally and Financially Liable for Scams on Skype? Legally, holding Microsoft accountable for scams on Skype is a complex issue because of existing laws that protect online platforms from liability for…

Read More
Investigators Link .4B Bybit Hack to North Korea’s Lazarus Group

Investigators Link $1.4B Bybit Hack to North Korea’s Lazarus Group

Bybit, the world’s second-largest cryptocurrency exchange, suffered a devastating $1.4 billion Ethereum (ETH) hack from a cold wallet breach on February 21, 2025. In the days following the attack, independent blockchain investigator ZachXBT traced the stolen funds directly to North Korea’s Lazarus Group, a notorious state-backed hacking organization. His findings were confirmed by Arkham Intelligence,…

Read More