NetBird is a legitimate remote access and tunneling tool that threat actors have abused to provide covert connectivity inside victim environments. In the provided reporting, VOID MANTICORE deployed NetBird on compromised systems, downloading it from the official site to build a zero-trust mesh network and tunnel traffic to internal hosts that were not directly reachable. This enabled control of multiple victim devices at once and supported lateral movement, which was otherwise conducted mainly over RDP. The content also states that newly observed TTPs included deployment of NetBird to tunnel traffic into victim networks. Separately, Trellix reported a spear-phishing campaign targeting CFOs and finance executives globally in the banking, energy, insurance, and investment sectors, where the actors sought to infect victims with a version of a NetBird remote access trojan. High-confidence associations in the content link NetBird abuse to VOID MANTICORE activity and to phishing-led intrusions against finance-focused targets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
VOID MANTICORE has installed NetBird on victim devices to create a mesh network that facilitated control of several victim devices at once.
Legitimate remote management tools, including Atera, AnyDesk, Syncro, SimpleHelp, and NetBird, were systematically abused to establish persistent remote access...
14 distinct techniques documented for this family, organized by ATT&CK tactic.
“Legitimate remote management tools … were systematically abused to establish persistent remote access, with attackers registering compromised trial accounts and impersonating credible organizations …”
In recent years, adversaries have increasingly relied on remote-access applications like this to establish persistence and further their way into the victim's network.
The Trellix article titled A Flyby on the CFO's Inbox details a sophisticated spear-phishing campaign targeting CFOs and finance executives... Attackers impersonated a Rothschild & Co recruiter, sending emails that led recipients through a deceptive CAPTCHA to download a ZIP file containing a malicious VBS script.
“Legitimate remote management tools … were systematically abused to establish persistent remote access, with attackers registering compromised trial accounts and impersonating credible organizations …”
To reach internal hosts not directly reachable, the group deploys NetBird—downloaded from the official site on compromised systems—to build a zero-trust mesh and tunnel traffic.
The attackers first connected to compromised hosts via RDP and then used the local web browser to download the software directly from the official NetBird website.
For persistence, the operator most frequently deployed rogue ScreenConnect clients configured to call back to attacker-controlled relay infrastructure, alongside Zoho Assist in several cases and, in one earlier instance, a Netbird and Atera combination
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access/mesh networking tool installed on victim devices to facilitate centralized control of multiple systems.
Zero-trust mesh networking and tunneling tool used by Void Manticore to reach internal hosts and facilitate lateral movement.
Legitimate mesh VPN/zero-trust networking tool abused to create internal connectivity and tunnel traffic, enabling operators to reach otherwise inaccessible internal hosts and coordinate hands-on activity from multiple footholds.
Legitimate remote access tool abused in spear-phishing operations to establish remote connectivity/control over victim environments.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.