logo

APT MuddyWater Targets CFOs with Multi-Stage Phishing & NetBird Abuse

ID: b126daa8-92d5-5707-9d9b-4de8193effd6

STIX ID: report--b126daa8-92d5-5707-9d9b-4de8193effd6

Feed Name: Hunt.io Blog

Threat Score
85/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This report documents a sophisticated, multi-stage spear-phishing campaign impersonating a Rothschild & Co recruiter that uses Firebase/web.app-hosted math CAPTCHA lures to deliver ZIP archives containing VBS droppers; the follow-on payloads (from 198.46.178.135) silently install NetBird and OpenSSH, create a hidden local admin account (user/Bs@202122), enable RDP, and add scheduled tasks for persistence. The investigation maps infrastructure pivots (192.3.95.152 → 198.46.178.135), enumerates numerous domains, files, and hashes as IOCs, highlights reuse of distinct phishing-kit AES logic across Firebase projects, and identifies overlaps with previously observed APT MuddyWater activity while recommending blocking IOCs, application allowlisting, and targeted EDR/SIEM detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.