Cybersecurity researchers are sounding the alarm about a new and highly targeted phishing campaignthat uses the legitimate remote access tool NetBird to bypass traditional security measures and infiltrate organizations.

The attack appears to be targeting Chief Financial Officers (CFOs) and senior finance executives at banks, energy companies, insurance companies and investment firms, in regions including Europe, Africa, Canada, the Middle East and South Asia.
See also: Ransomware groups abuse legitimate Kickidler software
According to Trellix, the campaign was first detected in mid-May 2025. While it has not yet been linked to any known threat actor, it exhibits alarming levels of sophistication. As researcher Srini Seethapathy explains, the attackers are using NetBird—a legitimate remote access tool—to gain control of victims’ systems.
The initial attack begins with a phishing email purporting to come from a recruiter at Rothschild & Co., offering “strategic opportunities.” The email includes a link that appears to be a PDF attachment, but actually redirects to a page hosted on Firebase.
What makes this attack different is that the URL is encrypted and not directly accessible. The victim is asked to pass a CAPTCHA, and only then is the malicious link revealed and activated, via JavaScript decryption. Finally, a ZIP file is downloaded.
“Cybercriminals are increasingly relying on custom CAPTCHA gates to evade detection mechanisms, such as Cloudflare Turnstile and Google reCAPTCHA,” explains Seethapathy.
See also: Phishing: Hackers abuse Google Apps Script
Along with the ZIP file is a Visual Basic Script (VBScript), which retrieves a second VBScript from a remote server and executes it via “wscript.exe”. This new script downloads another payload, renames it to “trm.zip” and extracts two MSI files from it: NetBird and OpenSSH.
The final phase of the attack involves installing the two applications on the infected computer, creating a hidden local account, enabling remote desktop access , and setting up scheduled tasks that ensure NetBird runs automatically on every reboot. At the same time, the malware removes any visible traces, such as shortcuts from the desktop, to avoid raising suspicions among the victim.

Trellix also identified a second active URL that has been distributing the same malicious VBScript for almost a year — an indication that the campaign may have been running for much longer than initially estimated.
The incident confirms a recent trend: cybercriminals are using legitimate remote access tools. In addition to NetBird, attackers are exploiting applications such as ConnectWise ScreenConnect, Atera, Splashtop, FleetDeck, and LogMeIn Resolve to maintain a persistent presence on targets' networks without being detected.
“This is not a simple phishing case,” said Srini Seethapathy of Trellix. “We are talking about a well-designed, targeted and subtle multi-stage scenario, combining social engineering with advanced evasion techniques, with the aim of maintaining persistent access to targets.”
See also: FBI: Warns of phishing attacks by Silent Ransom Group
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Protection measures
Security managers are urged to tools remote access installed on their organization's network to ensure that only authorized RMM solutions are being used.
Additionally, implementing policies that restrict the execution of unapproved RMM software is considered essential, as is the mandatory use of controlled remote access methods (such as VPN or VDI environments).
Finally, to enhance protection, it is recommended to block inbound and outbound connections to standard RMM ports and protocols.
Source: thehackernews.com
