Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Hackers misused IPV6 networking facility to hijack software updates
    Security

    Hackers misused IPV6 networking facility to hijack software updates

    PineapplesUpdateBy PineapplesUpdateMay 1, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Hackers misused IPV6 networking facility to hijack software updates
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers misused IPV6 networking facility to hijack software updates

    A China-focused APT danger actor named “Thewizards”, has attacked the Adv6 networking facility to launch Adversary-In-Middle (AITM) that updates kidnapping software to install Windows Malware.

    According to the ESET, the group has been active since at least 2022, targeting institutions in the Philippines, Cambodia, the United Arab Emirates, China and Hong Kong. The victims include individuals, gambling companies and other organizations.

    Attacks use a custom tool dubbed by ESET that misuses the IPV6 Stateless Address Autochonfigation (SLAAC) feature Slack attack,

    The Slaac IPV6 is a feature of the networking protocol that allows devices to automatically configure its own IP address and default gateway without the need for the DHCP server. Instead, it uses router advertising (RA) messages to get IP from the IPV6-supported router.

    The Spelbinder Tool of the hacker misused this feature by sending Spbed RA messages on the network, making the nearby systems automatically receive a new IPV6 IP address, new DNS server and a new, favorite IPV6 gateway.

    This default gateway, however, is the IP address of the spellbinder tool, which allows it to disrupt communication and reunion traffic through an attacker-controlled server.

    “Spelbinder a multicast RA packet sends every 200 MS to FF02 :: 1 (” all nodes “); Windows machines in the network with IPV6 competent through Autoconphiger Stateless address autoconfiguration (Slaac) using the information provided in the RA message, and start sending IPV6 traffic to the spellbinder running machine, where the packet will be intercepted, analyzed, and where applicable, will be replied, “ESET tells.

    Misuse of IPV6 Slaac using a spellbinder tool
    Misuse of IPV6 Slaac using a spellbinder tool
    Source: ESET

    ESET stated that deployment of spellbinder using a collection called avgapplicationframehosts.zip, which comes out in a directory mimicing valid software: “%programfiles%\ AVG technologies.”

    There are a valid copy of avgapplicationframehost.exe, wsc.dll, log.dat, and winpcap.exe within this directory. Winpcap executable is used to side-load the malicious wsc.dll, which loads the spellbinder into memory.

    Once a device becomes infected, the spellbinder begins to capture and analyze the network traffic to add specific domains, such as related to the Chinese software update server.

    ESET says that malware monitors for domains related to the following companies: Tencent, Baidu, Xunlei, Youku, Iqiyi, Kingsoft, Mango TV, Funshion, Yuodao, Xiaomi, Xiaomi Miui, PPLIVE, Meitu, Quihu 360, and Baofeng.

    The tool then redirect the requests that download and install malicious updates, which deploy a back door called “Vizardate”.

    The Vizardont Backdor continues to reach the infected device to the attackers and allows them to install additional malware as required.

    To protect against this type of attacks, organizations can monitor the IPV6 traffic or close the protocol if it is not necessary in their environment.

    In January, ESET also reported on another hacking group called “Blackwood”, kidnapping the WPS office software update facility to install malware.

    facility hackers hijack IPV6 misused networking Software updates
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleNow update your Apple devices to keep them safe from new airplay vulnerability
    Next Article These are the top franchises under $ 10,000 in 2025
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    How a simple link allowed hackers to bypass Copilot’s security guardrails – and what Microsoft did about it

    January 19, 2026
    Startups

    Verizon outage affects more than 2 million users: What ‘SOS’ means, refunds, more updates

    January 15, 2026
    Startups

    CES 2026 live updates: The latest news on TVs, smart glasses, phones and everything we’ve seen so far

    January 4, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.