{
  "Name": "NetBird",
  "Category": "RAT",
  "Description": "NetBird is an open-source WireGuard-based VPN and remote access platform that provides secure peer-to-peer connectivity. It has been observed being abused in spear-phishing campaigns across Europe, Africa, Canada, the Middle East, and South Asia, targeting CFOs and other financial executives at banks, energy companies, insurers, and investment firms. In May 2025, Trellix documented a campaign that impersonated a Rothschild & Co recruiter, leading victims through a deceptive CAPTCHA to download a ZIP containing a malicious VBScript that silently installed NetBird and OpenSSH MSI packages, created a hidden local administrator account, enabled RDP, and persisted the NetBird agent via a scheduled task — granting attackers persistent peer-to-peer remote access. Hunt.io and Trellix link the infrastructure to APT MuddyWater (Earth Vetala) based on overlap with previously documented activity (IP 192.3.95.152 / Gophish on TCP 3333).",
  "Author": "Michael Haag",
  "Created": "2026-01-15",
  "LastModified": "2026-05-04",
  "Details": {
    "Website": "https://netbird.io/",
    "PEMetadata": [
      {
        "Filename": "netbird.exe",
        "OriginalFileName": "",
        "Description": "NetBird client executable for Windows"
      },
      {
        "Filename": "netbird-ui.exe",
        "OriginalFileName": "",
        "Description": "NetBird UI executable for Windows"
      },
      {
        "Filename": "netbird",
        "OriginalFileName": "",
        "Description": "NetBird client binary for Linux/macOS"
      },
      {
        "Filename": "netbird_installer_*_windows_amd64.msi",
        "OriginalFileName": "",
        "Description": "NetBird Windows MSI installer (canonical naming pattern from official GitHub releases, e.g. netbird_installer_0.70.4_windows_amd64.msi). Renamed to netbird.msi in the May 2025 Trellix-reported campaign."
      },
      {
        "Filename": "netbird_installer_*_windows_amd64.exe",
        "OriginalFileName": "netbird_installer.exe",
        "Description": "NetBird Windows EXE installer signed by NetBird GmbH (formerly Wiretrustee UG). Description string \"Connect your devices into a secure WireGuard-based overlay network with SSO, MFA, and granular access controls.\" Product \"Netbird\"."
      },
      {
        "Filename": "wintun.dll",
        "OriginalFileName": "wintun.dll",
        "Description": "WireGuard Wintun TUN driver shipped with the NetBird Windows client."
      }
    ],
    "Privileges": "User",
    "Free": "Yes (Open Source)",
    "Verification": "Open Source",
    "SupportedOS": [
      "Windows",
      "Linux",
      "macOS",
      "Android",
      "iOS"
    ],
    "Capabilities": [
      "Remote Access",
      "VPN Connectivity",
      "Peer-to-Peer Networking",
      "Secure Tunneling",
      "Network Management"
    ],
    "Vulnerabilities": [],
    "InstallationPaths": [
      "C:\\Program Files\\Netbird\\netbird.exe",
      "C:\\Program Files\\Netbird\\netbird-ui.exe",
      "C:\\ProgramData\\Netbird\\*",
      "/usr/bin/netbird",
      "/usr/local/bin/netbird",
      "/opt/netbird/*",
      "/Applications/NetBird UI.app",
      "/etc/netbird/install.conf",
      "C:\\bin\\netbird.msi",
      "C:\\bin\\OpenSSH.msi",
      "C:\\bin\\cis.vbs",
      "C:\\bin\\trm.zip",
      "C:\\temper\\trm",
      "netbird.exe",
      "netbird-ui.exe",
      "netbird"
    ]
  },
  "Artifacts": {
    "Disk": [
      {
        "File": "C:\\Program Files\\Netbird\\netbird.exe",
        "Description": "NetBird client installation directory",
        "OS": "Windows"
      },
      {
        "File": "C:\\ProgramData\\Netbird\\config.json",
        "Description": "NetBird configuration file",
        "OS": "Windows"
      },
      {
        "File": "/etc/netbird/config.json",
        "Description": "NetBird configuration file",
        "OS": "Linux"
      },
      {
        "File": "/var/log/netbird/*",
        "Description": "NetBird log files",
        "OS": "Linux"
      },
      {
        "File": "/etc/netbird/install.conf",
        "Description": "NetBird installation manifest written by the official install.sh — records the package manager type used.",
        "OS": "Linux"
      },
      {
        "File": "/Applications/NetBird UI.app",
        "Description": "NetBird UI application bundle on macOS (installed via .pkg or Homebrew cask).",
        "OS": "macOS"
      },
      {
        "File": "C:\\bin\\netbird.msi",
        "Description": "NetBird MSI dropped by the May 2025 Trellix-reported CFO spear-phishing campaign (silently installed by cis.vbs / Stage-2 VBS).",
        "OS": "Windows"
      },
      {
        "File": "C:\\bin\\OpenSSH.msi",
        "Description": "OpenSSH server MSI dropped alongside NetBird in the May 2025 CFO spear-phishing campaign (used to enable persistent SSH access).",
        "OS": "Windows"
      },
      {
        "File": "C:\\bin\\cis.vbs",
        "Description": "Stage-2 VBScript dropper that installs NetBird and OpenSSH (May 2025 Trellix-reported campaign).",
        "OS": "Windows"
      },
      {
        "File": "C:\\bin\\trm.zip",
        "Description": "ZIP staging archive containing NetBird and OpenSSH MSIs (renamed from \"trm\" payload fetched from the C2).",
        "OS": "Windows"
      },
      {
        "File": "C:\\temper\\trm",
        "Description": "Initial payload staging path used by the Stage-1 VBScript before being renamed to trm.zip (May 2025 campaign).",
        "OS": "Windows"
      }
    ],
    "EventLog": [
      {
        "EventID": 4688,
        "Description": "Process creation event for netbird.exe",
        "OS": "Windows"
      },
      {
        "EventID": 7045,
        "Description": "Service installation event for NetBird",
        "OS": "Windows"
      },
      {
        "EventID": 4720,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "Description": "A user account was created. Observed during May 2025 CFO spear-phishing campaign — local account \"user\" created with password \"Bs@202122\".",
        "OS": "Windows"
      },
      {
        "EventID": 4732,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "Description": "A member was added to a security-enabled local group. Observed during May 2025 CFO spear-phishing campaign — \"user\" added to Administrators / Administrateurs.",
        "OS": "Windows"
      },
      {
        "EventID": 4698,
        "ProviderName": "Microsoft-Windows-Security-Auditing",
        "LogFile": "Security.evtx",
        "Description": "A scheduled task was created. Observed during May 2025 CFO spear-phishing campaign — task \"ForceNetbirdRestart\" created to restart NetBird one minute after boot.",
        "OS": "Windows"
      }
    ],
    "Registry": [
      {
        "Path": "HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\UserList\\user",
        "Description": "Registry key set to 0 to hide the attacker-created local administrator account \"user\" from the Windows logon screen (May 2025 Trellix-reported CFO spear-phishing campaign)."
      },
      {
        "Path": "HKLM\\SYSTEM\\CurrentControlSet\\Services\\Netbird",
        "Description": "Netbird Windows service registration (created by NetBird MSI installer; configured by the campaign for delayed automatic start at boot)."
      }
    ],
    "Network": [
      {
        "Description": "NetBird control-plane and client endpoints (canonical, from official documentation)",
        "Domains": [
          "netbird.io",
          "*.netbird.io",
          "api.netbird.io",
          "app.netbird.io",
          "signal.netbird.io",
          "relay.netbird.io",
          "login.netbird.io",
          "pkgs.netbird.io"
        ],
        "Ports": [
          443,
          33073,
          51820
        ]
      },
      {
        "Description": "Threat actor C2 / staging infrastructure observed in the May 2025 Trellix-reported CFO spear-phishing campaign and Hunt.io follow-up. Overlaps with APT MuddyWater (Earth Vetala) infrastructure.",
        "Domains": [
          "192.3.95.152",
          "198.46.178.135",
          "googl-6c11f.firebaseapp.com",
          "googl-6c11f.web.app",
          "googl-165a0.web.app",
          "cloud-ed980.firebaseapp.com",
          "cloud-233f9.firebaseapp.com",
          "my-sharepoint-inc.com",
          "my1cloudlive.com",
          "my2cloudlive.com",
          "web-16fe.app"
        ],
        "Ports": [
          80,
          443,
          3333
        ]
      }
    ],
    "Other": [
      {
        "Type": "NetworkInterface",
        "Value": "wt0"
      },
      {
        "Type": "NetworkInterface",
        "Value": "utun100"
      },
      {
        "Type": "ServiceName",
        "Value": "Netbird"
      },
      {
        "Type": "SetupKey",
        "Value": "E48E4A70-4CF4-4A77-946B-C8E50A60855A"
      },
      {
        "Type": "ScheduledTask",
        "Value": "ForceNetbirdRestart"
      },
      {
        "Type": "LocalUser",
        "Value": "user"
      },
      {
        "Type": "SHA256",
        "Value": "b8c84e7047080589cc2e1dc955c78349f8d37d0e79160a040096e1ffcf89d869"
      },
      {
        "Type": "SignerSubject",
        "Value": "NetBird GmbH (current; chain GlobalSign GCC R45 EV CodeSigning CA 2020 -> GlobalSign Code Signing Root R45)"
      },
      {
        "Type": "SignerSubject",
        "Value": "Wiretrustee UG (haftungsbeschränkt) (legacy; chain SSL.com EV Code Signing Intermediate CA RSA R3 -> SSL.com EV Root Certification Authority RSA R2)"
      }
    ]
  },
  "Detections": [],
  "References": [
    "https://github.com/magicsword-io/LOLRMM/issues/81",
    "https://www.trellix.com/en-in/blogs/research/a-flyby-on-the-cfos-inbox-spear-phishing-campaign-targeting-financial-executives-with-netbird-deployment/",
    "https://hunt.io/blog/apt-muddywater-deploys-multi-stage-phishing-to-target-cfos",
    "https://netbird.io/knowledge-hub/netbird-response-to-spear-phishing-campaign-targeting-financial-executives",
    "https://www.centripetal.ai/threat-research/threat-actors-abuse-netbird-in-spear-phishing-campaign-targeting-finance-executives",
    "https://thehackernews.com/2025/06/fake-recruiter-emails-target-cfos-using.html",
    "https://netbird.io/use-cases/remote-access",
    "https://docs.netbird.io/how-to/installation",
    "https://github.com/netbirdio/netbird",
    "https://github.com/netbirdio/netbird/releases/latest"
  ],
  "Acknowledgement": [
    {
      "Person": "jacobholtz",
      "Handle": "@jacobholtz"
    },
    {
      "Person": "ruppde",
      "Handle": "@ruppde"
    }
  ]
}