216.73.216.6

APT MuddyWater Targets CFOs with Multi-Stage Phishing & NetBird Abuse

· Published 21/08/2025 07:35 · Modified 21/08/2025 12:22

Export JSON

Essential information

Published
21/08/2025 07:35
Modified
21/08/2025 12:22
Tags
2025-08-21 apt ateraagent cfo finance firebase multi-stage netbird remote access spear-phishing vbs
Related entities
1 intrusion sets (apt), 2 malware, 4 others

Description

A sophisticated campaign, likely linked to MuddyWater, is targeting CFOs and executives across multiple continents. The attackers use -hosted phishing pages with custom CAPTCHA challenges, malicious scripts, and payload delivery to deploy , a legitimate remote-access tool, for persistent system control. The campaign employs social engineering tactics, impersonating a Rothschild & Co recruiter to lure victims. Analysis revealed evolving infrastructure, updated payload paths, and overlaps with known MuddyWater activities. The attackers abuse legitimate tools like and for and monitoring, while using sophisticated techniques such as AES encryption and math-based CAPTCHA lures to evade detection.

External references