Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    How a heritage hardware company established itself in the AI ​​era

    August 30, 2025

    A week later with Google Pixel 10, I am wondering why anyone should buy a pricier flagship

    August 30, 2025

    This is my top pick for both del laptop work and travel – especially at this price

    August 30, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Hackers misused IPV6 networking facility to hijack software updates
    Security

    Hackers misused IPV6 networking facility to hijack software updates

    PineapplesUpdateBy PineapplesUpdateMay 1, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Hackers misused IPV6 networking facility to hijack software updates
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers misused IPV6 networking facility to hijack software updates

    A China-focused APT danger actor named “Thewizards”, has attacked the Adv6 networking facility to launch Adversary-In-Middle (AITM) that updates kidnapping software to install Windows Malware.

    According to the ESET, the group has been active since at least 2022, targeting institutions in the Philippines, Cambodia, the United Arab Emirates, China and Hong Kong. The victims include individuals, gambling companies and other organizations.

    Attacks use a custom tool dubbed by ESET that misuses the IPV6 Stateless Address Autochonfigation (SLAAC) feature Slack attack,

    The Slaac IPV6 is a feature of the networking protocol that allows devices to automatically configure its own IP address and default gateway without the need for the DHCP server. Instead, it uses router advertising (RA) messages to get IP from the IPV6-supported router.

    The Spelbinder Tool of the hacker misused this feature by sending Spbed RA messages on the network, making the nearby systems automatically receive a new IPV6 IP address, new DNS server and a new, favorite IPV6 gateway.

    This default gateway, however, is the IP address of the spellbinder tool, which allows it to disrupt communication and reunion traffic through an attacker-controlled server.

    “Spelbinder a multicast RA packet sends every 200 MS to FF02 :: 1 (” all nodes “); Windows machines in the network with IPV6 competent through Autoconphiger Stateless address autoconfiguration (Slaac) using the information provided in the RA message, and start sending IPV6 traffic to the spellbinder running machine, where the packet will be intercepted, analyzed, and where applicable, will be replied, “ESET tells.

    Misuse of IPV6 Slaac using a spellbinder tool
    Misuse of IPV6 Slaac using a spellbinder tool
    Source: ESET

    ESET stated that deployment of spellbinder using a collection called avgapplicationframehosts.zip, which comes out in a directory mimicing valid software: “%programfiles%\ AVG technologies.”

    There are a valid copy of avgapplicationframehost.exe, wsc.dll, log.dat, and winpcap.exe within this directory. Winpcap executable is used to side-load the malicious wsc.dll, which loads the spellbinder into memory.

    Once a device becomes infected, the spellbinder begins to capture and analyze the network traffic to add specific domains, such as related to the Chinese software update server.

    ESET says that malware monitors for domains related to the following companies: Tencent, Baidu, Xunlei, Youku, Iqiyi, Kingsoft, Mango TV, Funshion, Yuodao, Xiaomi, Xiaomi Miui, PPLIVE, Meitu, Quihu 360, and Baofeng.

    The tool then redirect the requests that download and install malicious updates, which deploy a back door called “Vizardate”.

    The Vizardont Backdor continues to reach the infected device to the attackers and allows them to install additional malware as required.

    To protect against this type of attacks, organizations can monitor the IPV6 traffic or close the protocol if it is not necessary in their environment.

    In January, ESET also reported on another hacking group called “Blackwood”, kidnapping the WPS office software update facility to install malware.

    facility hackers hijack IPV6 misused networking Software updates
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleNow update your Apple devices to keep them safe from new airplay vulnerability
    Next Article These are the top franchises under $ 10,000 in 2025
    PineapplesUpdate
    • Website

    Related Posts

    Security

    How a heritage hardware company established itself in the AI ​​era

    August 30, 2025
    Security

    Microsoft to implement MFA for Azure Resource Management in October

    August 30, 2025
    Security

    Netscaler adc and gateway exploiting Zero de Flaw, Citrix warns

    August 30, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    How a heritage hardware company established itself in the AI ​​era

    August 30, 2025

    A week later with Google Pixel 10, I am wondering why anyone should buy a pricier flagship

    August 30, 2025

    This is my top pick for both del laptop work and travel – especially at this price

    August 30, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.