Sunday, September 6, 2026

New Spear-Phishing Campaign Targets Financial Executives with NetBird Malware

Trellix’s email security systems detected a highly targeted spear-phishing campaign aimed at CFOs and finance executives across industries like banking, energy, insurance, and investment firms in regions spanning Europe, Africa, Canada, the Middle East, and South Asia.

This meticulously crafted operation, uncovered by Trellix’s Advanced Research Center, leverages social engineering to impersonate a Rothschild & Co recruiter, dangling a “confidential leadership opportunity” as bait.

Sophisticated Multi-Stage Attack

What sets this campaign apart is its use of legitimate tools like NetBird a WireGuard-based remote access software and OpenSSH to establish persistent access to victims’ networks, showcasing a alarming trend of adversaries weaponizing trusted applications for malicious intent.

NetBird Malware
Spear-Phishing Campaign Installing Netbird and Enabling Remote Access

The attack infrastructure partially overlaps with other nation-state campaigns deploying remote access tools, though no specific threat group has been attributed yet.

Technical Breakdown of the Attack Chain

The attack begins with a deceptive email titled “Rothschild & Co leadership opportunity (Confidential),” urging recipients to view an attached “brochure” named Rothschild_&Co-6745763.PDF.

This file is not a PDF but a phishing link redirecting to a Firebase-hosted page (hxxps://googl-6c11f.firebaseapp[.]com) protected by a custom math CAPTCHA designed to evade traditional security defenses like Cloudflare Turnstile or Google reCAPTCHA.

NetBird Malware
Final Redirected Webpage

Solving the CAPTCHA decrypts a hidden URL, leading to a ZIP file download (Rothschild&_Co-6745763.zip).

Once extracted, the ZIP reveals a VBS script that creates a directory at C:\temper\ and fetches a secondary VBS payload (pull.vbs) from a command-and-control (C2) server at 192[.]3[.]95[.]152.

This second script silently installs NetBird and OpenSSH via MSI packages, starts their services, and configures NetBird with a preset setup key for remote access.

Additionally, it creates a hidden local admin account (“user” with password “Bs@202122”), enables Remote Desktop Protocol (RDP) with firewall adjustments, and sets up scheduled tasks to ensure persistence across reboots.

This multi-stage approach, combining defense evasion (e.g., bypassing UAC via “runas”), privilege escalation, and lateral movement capabilities through RDP and SSH, underscores the sophistication of the threat.

Trellix also identified related infrastructure, including older phishing pages with identical CAPTCHA tactics, indicating a broader campaign footprint, while France’s AMF recently warned of similar impersonation attacks with overlapping indicators.

Trellix advises executives to treat unsolicited recruitment emails with suspicion, avoid enabling scripts from unknown downloads, and report anomalies to security teams promptly.

For defenders, deploying Endpoint Detection and Response (EDR) solutions, monitoring suspicious script executions (via wscript.exe or PowerShell), auditing MSIExec activity, and tracking new local accounts are critical steps to mitigate such threats.

Indicators of Compromise

Indicator TypeValueContext / Purpose
Email SubjectRothschild & Co leadership opportunity (Confidential)Subject of social engineering email
IP Address (C2/Hosting)192[.]3[.]95[.]152Hosts stage-2 payloads
URL – Stage-0 (Firebase)hxxps://googl-6c11f.firebaseapp[.]com/job/file-846873865383.htmlPhishing page with custom CAPTCHA
URL – ZIP DownloadRothschild_&_Co-6745763.zipArchive contains stage-1 VBS
Local Admin Accountuser / Bs@202122Hidden account added to Administrators
NetBird Setup KeyE48E4A70-4CF4-4A77-946B-C8E50A60855AUsed for NetBird configuration

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Chainguard Hits 1 Billion Build Manifests With AI-Powered Software Supply Chain Security

Chainguard has surpassed 1 billion container build manifests, doubling...

Russian Hackers Deploy New HOOKEDGE Backdoor in Espionage Attacks Across Europe

Russian state-sponsored threat actor BlueDelta, also tracked as APT28,...

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption

Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS)...

12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers

A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged...

Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours

A threat actor used frontier artificial-intelligence models and attack-specific...

CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each

Used-car platform CARS24 has alleged that confidential information belonging...

Hackers Turn HiveMQ and Element Messenger Into Control Channels for Windows Backdoors

The financially motivated threat actor Toy Ghouls has expanded...

Related Articles

Recent News