October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
CFO security

Fake Recruiter Emails Targeted CFOs With Legitimate NetBird Tool: What Happened in 2025

Trellix reported a 2025 campaign targeting CFOs with a fake Rothschild & Co recruitment offer. The infection chain used Firebase, a CAPTCHA, VBScript, NetBird, OpenSSH, a hidden administrator and RDP.

By TheFinanceBase Team 7 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: Trellix detected a May 15, 2025 spear-phishing campaign that impersonated a Rothschild & Co recruiter and targeted CFOs and other senior finance staff. Victims were steered through a Firebase-hosted page and a fake CAPTCHA, then offered a ZIP file containing a Visual Basic script. The script attempted to install legitimate NetBird remote-access software and OpenSSH, create a hidden administrator account, enable RDP, and establish automatic startup. Trellix and NetBird reported abuse of the software after administrative access was obtained—not a vulnerability in NetBird itself.

The campaign was reported across 11 named countries. The “six global regions” wording used in some coverage is imprecise because Trellix’s narrative and country table do not use one consistent six-region classification.

The campaign in one minute

  1. A confidential executive-recruitment email impersonated a Rothschild & Co employee.
  2. A link presented what appeared to be a PDF or presentation about a senior finance opportunity.
  3. A Firebase-hosted page displayed a custom CAPTCHA or simple math puzzle.
  4. JavaScript decrypted a hidden redirect after the challenge, leading to a ZIP download.
  5. The archive contained a VBScript, not a genuine recruitment document.
  6. The script downloaded more content and silently installed NetBird and OpenSSH.
  7. It created a hidden local administrator, enabled RDP, configured services and a scheduled task, and removed visible shortcuts.

Trellix published its technical report on May 28, 2025. NetBird issued a response on May 29, and The Hacker News summarized the incident on June 2. The available reporting describes a 2025 campaign; it does not establish that the activity remained active in 2026.

Who was targeted and why

Trellix said the messages targeted CFOs and other senior finance personnel in high-value industries, including banking, insurance, energy, investment, mining, semiconductors and tourism-related businesses. Its country-and-sector table named targets in:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • United Kingdom
  • Canada
  • South Africa
  • Norway
  • South Korea
  • Singapore
  • Switzerland
  • France
  • Egypt
  • Saudi Arabia
  • Brazil

Executives are attractive targets because their devices and accounts may expose financial information, payment workflows, board materials, investor communications and broad internal trust. They also regularly interact with recruiters, advisers, banks and prospective partners, making a polished “confidential opportunity” harder to dismiss than a generic malware email.

What the recruitment email looked like

The reported subject was “Rothschild & Co leadership opportunity ( Confidential )”. The message presented a senior-level financial leadership opportunity and encouraged the recipient to open a document. Trellix reported a mismatch between the apparent sender and the reply-to address, including db2680688@gmail[.]com.

The important warning is contextual credibility. The lure did not need obvious grammatical errors or a crude counterfeit logo; it used a plausible executive scenario, confidentiality language and a recognizable financial brand. Verify an unsolicited approach through a phone number or corporate channel obtained independently, rather than replying to the message or using its links.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Why the CAPTCHA was part of the attack

The CAPTCHA was a delivery and evasion gate, not protection for the visitor. Trellix found that the page stored its real destination in encrypted form. JavaScript decrypted the redirect only after the user completed the puzzle, which can complicate automated URL inspection and create a misleading impression of legitimacy.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Trellix said its URL-defense engine blocked the initial URL because of suspicious CAPTCHA behavior. That illustrates two limits: a security product may detect the delivery page even when domain reputation looks normal, and a page that asks you to solve a challenge is not necessarily safe.

Technical infection chain

From document link to script

The supposed PDF was effectively a link or HTML-based delivery mechanism. After the CAPTCHA, the victim was offered an archive named similarly to a recruitment document, reported as Rothschild_&_Co-6745763.zip. Inside was Rothschild_&_Co-6745763.vbs. When run with wscript.exe, the script retrieved a second-stage script called pull.vbs and additional payloads.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Silent software installation

Trellix observed silent MSI installation of NetBird and OpenSSH. The reported additional payload was renamed trm.zip. The script behavior required administrative privileges for the installation and service changes; NetBird specifically emphasized that the attacker had already gained those privileges through the malicious execution chain.

Persistence and fallback access

The observed host changes included a local account named user added to administrative access and configured to remain hidden, changes that enabled RDP and its firewall rule, services set to start automatically, and a scheduled task to restart NetBird. Desktop shortcuts were removed to reduce visible clues.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OpenSSH supplied another remote path alongside NetBird and RDP. The combination gave an attacker several ways to return, although the public report does not prove that every step succeeded on every recipient or document what was done after access.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What NetBird did—and did not do

NetBird is a legitimate open-source, WireGuard-based networking and remote-access tool. In this incident it was the remote-access mechanism installed after the victim had been induced to run a malicious script with administrative rights. Trellix did not report a NetBird vulnerability. NetBird said the campaign used unauthorized installation and a valid administrative configuration, and that it blocked the malicious actors and terminated related access after notification.

That distinction matters operationally. NetBird on an endpoint is not proof of compromise: an organization may use it legitimately. The relevant question is whether the installation, identity, setup and network activity are approved for that device and user.

Indicators and telemetry to investigate

Email and web controls

  • Cold outreach offering senior finance, board or advisory roles.
  • Sender and reply-to mismatches.
  • New or low-reputation Firebase and web-app URLs.
  • URL chains involving firebaseapp.com and web.app.
  • CAPTCHA pages that perform client-side decryption or redirecting.
  • ZIP downloads from recruitment-themed messages.

Endpoint and identity controls

  • wscript.exe launched on a user workstation, especially one assigned to finance leadership.
  • VBScript making outbound HTTP requests.
  • msiexec.exe installing NetBird or OpenSSH outside approved deployment.
  • Unexpected local administrator creation, hidden accounts or administrator-group changes.
  • RDP registry changes, newly enabled RDP firewall rules, or new sshd and netbird services.
  • Scheduled tasks that start remote-access services.
  • Removal of expected application shortcuts.

Useful reported artifacts include the defanged lure domain googl-6c11f.firebaseapp[.]com, redirect domain googl-6c11f.web[.]app, reported command-and-control address 192[.]3[.]95[.]152, filenames above, and hashes 4cd73946b68b2153dbff7dee004012c3, 53192ba6a65a6abd44f167b3a8d0e52d and b91162a019934b9cb3c084770ac03efe. Treat these as hunt leads, not complete detection coverage; attackers can change filenames and infrastructure.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What executives should do

  1. Verify the recruiter through a known company website, switchboard or existing contact.
  2. Do not open ZIP archives or run scripts supplied in unsolicited outreach.
  3. Do not treat a CAPTCHA as proof that a page is trustworthy.
  4. Report the message even if you did not click.
  5. If you opened a file, follow your incident-response policy to disconnect the device and contact security immediately.
  6. Do not delete the email, archive or browser history before responders collect evidence.

Incident-response priorities

  1. Isolate the endpoint while preserving volatile evidence.
  2. Suspend the suspicious local account and remove unauthorized administrator access.
  3. Revoke unauthorized NetBird access and terminate related sessions.
  4. Disable unexpected RDP and OpenSSH services.
  5. Review services, scheduled tasks, firewall changes, registry changes and administrator-group membership.
  6. Collect headers, URLs, archives, scripts, hashes and endpoint telemetry.
  7. Hunt across the environment for the reported domains, address, filenames and hashes.
  8. Rotate credentials and tokens used on the device, prioritizing privileged, finance, identity, VPN and cloud accounts.
  9. Review lateral-movement and data-access logs.
  10. Reimage or restore the endpoint when persistence cannot be confidently removed.

Controls that reduce recurrence

  • Use allowlists, ownership records and device-posture checks for remote-access software rather than relying only on product-name blocking.
  • Sandbox ZIP attachments, block archives containing active scripts where practical, and test any VBScript restrictions against legacy dependencies.
  • Correlate email, identity, endpoint and Windows service-change telemetry; phishing training alone is insufficient for personalized lures.
  • Monitor executive endpoints for new local administrators, RDP changes, unexpected SSH services and script interpreters.
  • Do not assume MFA will stop a compromise after local administrator access or a remote session is established.

What the public record does not establish

The sources do not provide a victim count, confirmed number of successful compromises, confirmed data theft, financial losses, or a named threat actor. Trellix noted infrastructure overlap with another nation-state spear-phishing campaign involving remote-access tools, but did not attribute this activity to a known group. A blocked URL also does not prove that no alternate delivery path reached a user.

Timeline and sources

Date Event
May 15, 2025 Trellix email-security products detected the campaign.
May 28, 2025 Trellix published its technical report.
May 29, 2025 NetBird published its response.
June 2, 2025 The Hacker News published its account.

Primary reporting: Trellix technical analysis, NetBird response, and The Hacker News summary.

Frequently Asked Questions

Does finding NetBird on a CFO’s computer prove an attack occurred?

No. NetBird can be legitimate. Investigate whether its installation, identity, setup and network activity were approved, and correlate it with script execution, account changes, RDP or scheduled-task activity.

Should companies block every ZIP attachment or remote-access product?

Not necessarily. Broad blocking can disrupt legitimate work. Use allowlists, sandboxing, archive-content inspection, ownership records and behavior-based detections, with stricter controls for executive endpoints.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was a specific nation-state group identified?

No. Trellix reported infrastructure overlap with another campaign but did not attribute this activity to a named threat actor.

The Bottom Line

The campaign weaponized trust in an executive-recruitment context and then hid persistence behind legitimate administration tools. Defending against similar attacks requires coordinated email, endpoint, identity and remote-access governance—not a blacklist of NetBird alone.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Money Desk

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.