None
EN
TheWizards APT group uses SLAAC spoofing to perform adversary-in-the-middle attacks
[]
WeLiveSecurity
The recursive DNS server (RDNSS) option that provides the host with the addresses of two DNS servers: 240e:56:4000:8000::11 and 240e:56:4000:8000::22 .
We have not found any evidence indicating that either is a legitimate DNS server.
We have not found any evidence indicating that either is a legitimate DNS server.
The malicious server that issues the update instructions was still active at the time of writing.
DA867188937698C77698 61C72F5490CB9C3D4F63 N/A Win64/Agent.CAZ Spellbinder tool (2023), loaded in memory.
['adversaryinthemiddle'
'thewizards'
'perform'
'network'
'spoofing'
'malicious'
'used'
'ipv6'
'group'
'packet'
'named'
'slaac'
'attacks'
'dns'
'spellbinder'
'tool'
'server'
'uses'
'apt']