Fake Recruiter Emails Target CFOs Using Legit NetBird Tool Across 6 Global Regions
Researchers studying cybersecurity have issued a warning about a new spear-phishing campaign that targets Chief Financial Officers (CFOs) and financial executives at banks, energy companies, insurance companies, and investment firms in Europe, Africa, Canada, the Middle East, and South Asia using a phony remote access tool called Netbird.
According to an investigation by Trellix researcher Srini Seethapathy, the attackers sought to install NetBird, a genuine wireguard-based remote access program, on the victim's machine in what seems to have been a multi-stage phishing campaign.
The cybersecurity firm initially discovered the behavior in mid-May 2025, but no known threat actor or group has been linked to it.
The campaign begins with a phishing email purporting to be from a Rothsc...

