Fake Recruiter Emails Target CFOs Using Legit NetBird Tool Across 6 Global Regions https://t.co/DLtPPxTbVP
Fake Recruiter Emails Target CFOs Using Legit NetBird Tool Across 6 Global Regions: https://t.co/B0x8hrVST5 by The Hacker News #infosec #cybersecurity #technology #news
👀 “Strategic Opportunity” or Silent Backdoor? CFOs across Europe, Africa, & Asia are being hunted in a stealth phishing op impersonating Rothschild recruiters. Victims solve a CAPTCHA—then unknowingly install NetBird & OpenSSH, giving attackers remote access. It’s legit https://t.co/ef7PwKU4SL
A coordinated phishing campaign has been identified targeting financial executives, particularly chief financial officers (CFOs), across Europe, Africa, and Asia. The attackers impersonate recruiters from Rothschild, a prominent financial institution, to deceive victims into completing a CAPTCHA that leads to the installation of legitimate remote access tools NetBird and OpenSSH. This tactic grants cybercriminals unauthorized remote access to the victims' systems. Additionally, a related phishing operation observed by GTIG targets European government organizations using signed .rdp attachments to initiate Remote Desktop Protocol connections, highlighting a broader trend of sophisticated cyber intrusions leveraging trusted software to bypass security defenses.