Chinese Hackers Abuse IPv6 SLAAC for AitM Attacks via Spellbinder Lateral Movement Tool
A China-aligned advanced persistent threat (APT) group called
TheWizards has been linked to a lateral movement tool called
Spellbinder that can facilitate adversary-in-the-middle (AitM)
attacks. "Spellbinder enables adversary-in-the-middle (AitM)
attacks, through IPv6 stateless address autoconfiguration (SLAAC)
spoofing, to move laterally in the compromised network,
intercepting packets and
Read more https://thehackernews.com/2025/04/chinese-hackers-abuse-ipv6-slaac-for.html