Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 15:39:02 UTC Home > List all groups > List all tools > List all groups using tool WizardNet Tool: WizardNet Names WizardNet Category Malware Type Backdoor Description (ESET) The final payload is a backdoor that we named WizardNet – a modular implant that connects to a remote controller to receive and execute .NET modules on the compromised machine. Information Last change to this tool card: 27 June 2025 Download this tool card in JSON format All groups using tool WizardNet Changed Name Country Observed APT groups TheWizards 2022 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=762e69a7-6a49-487f-952f-265dfeccc025 https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=762e69a7-6a49-487f-952f-265dfeccc025 Page 1 of 1