[GH-ISSUE #6024] Netbird Installer/Uninstaller detected as malware #12713

Closed
opened 2026-08-05 02:06:31 -04:00 by saavagebueno · 24 comments
Owner

Originally created by @TobiKr on GitHub (Apr 29, 2026).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/6024

The Netbird Installer and Uninstaller is detected as Malware by Micrososft Defender for Endpoint in Windows. This is usually solved over time when the install base increases but not really a solution due to the very short release interval.

Possible solution: sign all executables with netbird Signing Cert. Currently only netbird.exe and netbird-ui.exe is signed, but netbird-uninstall.exe is not. After signing the uninstaller, the "trust" is higher and false positives should be less, also it allows organizations to whitelist the signing certificate and not just the Hash of each individual uninstaller.

Originally created by @TobiKr on GitHub (Apr 29, 2026). Original GitHub issue: https://github.com/netbirdio/netbird/issues/6024 The Netbird Installer and Uninstaller is detected as Malware by Micrososft Defender for Endpoint in Windows. This is usually solved over time when the install base increases but not really a solution due to the very short release interval. Possible solution: sign all executables with netbird Signing Cert. Currently only netbird.exe and netbird-ui.exe is signed, but netbird-uninstall.exe is not. After signing the uninstaller, the "trust" is higher and false positives should be less, also it allows organizations to whitelist the signing certificate and not just the Hash of each individual uninstaller.
saavagebueno added the triage-needed label 2026-08-05 02:06:31 -04:00
Author
Owner

@mrwsl commented on GitHub (Apr 29, 2026):

This also prevents winget from seeing updates: https://github.com/microsoft/winget-pkgs/pull/365526

<!-- gh-comment-id:4341992874 --> @mrwsl commented on GitHub (Apr 29, 2026): This also prevents winget from seeing updates: https://github.com/microsoft/winget-pkgs/pull/365526
Author
Owner

@id6tm-mteterel commented on GitHub (Apr 29, 2026):

The installer also triggers SmartScreen on my end since a few versions, despite being signed.

<!-- gh-comment-id:4344282192 --> @id6tm-mteterel commented on GitHub (Apr 29, 2026): The installer also triggers SmartScreen on my end since a few versions, despite being signed.
Author
Owner

@tommy10606 commented on GitHub (Apr 29, 2026):

I am seeing the same thing. Trojan:Script/Wacatac.H!ml

<!-- gh-comment-id:4344952995 --> @tommy10606 commented on GitHub (Apr 29, 2026): I am seeing the same thing. Trojan:Script/Wacatac.H!ml
Author
Owner

@tommy10606 commented on GitHub (Apr 30, 2026):

Issue still exists in version 0.70.4

<!-- gh-comment-id:4352496259 --> @tommy10606 commented on GitHub (Apr 30, 2026): Issue still exists in version 0.70.4
Author
Owner

@SteveW94 commented on GitHub (Apr 30, 2026):

I am also seeing Trojan:Script/Wacatac.H!ml, chrome even refuses the download atm.

<!-- gh-comment-id:4355191624 --> @SteveW94 commented on GitHub (Apr 30, 2026): I am also seeing Trojan:Script/Wacatac.H!ml, chrome even refuses the download atm.
Author
Owner

@sunstarjeff commented on GitHub (Apr 30, 2026):

This issue persists in version 0.70.4. It's not an easy sell to install updates in a server environment (especially a client's network).

<!-- gh-comment-id:4357517336 --> @sunstarjeff commented on GitHub (Apr 30, 2026): This issue persists in version 0.70.4. It's not an easy sell to install updates in a server environment (especially a client's network).
Author
Owner

@JerBar commented on GitHub (May 1, 2026):

GET THIS FIXED..

This is adding SOO Much paperwork for me. I have to fill out incidents for EVERY machine that this just got flagged on.
there goes my weekend.

<!-- gh-comment-id:4359181676 --> @JerBar commented on GitHub (May 1, 2026): GET THIS FIXED.. This is adding SOO Much paperwork for me. I have to fill out incidents for EVERY machine that this just got flagged on. there goes my weekend.
Author
Owner

@TobiKr commented on GitHub (May 1, 2026):

I flagged one of the team members via slack

<!-- gh-comment-id:4359308317 --> @TobiKr commented on GitHub (May 1, 2026): I flagged one of the team members via slack
Author
Owner

@emrcbrn commented on GitHub (May 5, 2026):

Hi all,

We're definitely aware of this issue & apologize for the inconvenience caused by this. For some background information that we changed the signature on our package as the other certificate was expiring.

With that change, we replaced the organization signing it to our legal name NetBird GmbH. This caused a reset on our software reputation.

This is a process that should take a few more days to improve as various Anti-Virus vendors re-assess their ratings, but it depends on multiple users submitting the app for analysis as false positive as well. You can do so to Windows Defender here as well as ESET here.

We've already filed the reports on our end to classify these as false-positives, but all reports help as quantity matters - so thanks for the help!

<!-- gh-comment-id:4379709545 --> @emrcbrn commented on GitHub (May 5, 2026): Hi all, We're definitely aware of this issue & apologize for the inconvenience caused by this. For some background information that we changed the signature on our package as the other certificate was expiring. With that change, we replaced the organization signing it to our legal name `NetBird GmbH`. This caused a reset on our software reputation. This is a process that should take a few more days to improve as various Anti-Virus vendors re-assess their ratings, but it depends on multiple users submitting the app for analysis as false positive as well. You can do so to [Windows Defender here](https://www.microsoft.com/en-us/wdsi/filesubmission) as well as [ESET here](https://support.eset.com/en/kb141-submit-a-virus-website-or-potential-false-positive-sample-to-the-eset-lab). We've already filed the reports on our end to classify these as false-positives, but all reports help as quantity matters - so thanks for the help!
Author
Owner

@SteveW94 commented on GitHub (May 5, 2026):

I can report, that with latest windows defender definition it's not an issue anymore :)

<!-- gh-comment-id:4379956791 --> @SteveW94 commented on GitHub (May 5, 2026): I can report, that with latest windows defender definition it's not an issue anymore :)
Author
Owner

@Geertkok1 commented on GitHub (May 6, 2026):

Hi all,

We're definitely aware of this issue & apologize for the inconvenience caused by this. For some background information that we changed the signature on our package as the other certificate was expiring.

With that change, we replaced the organization signing it to our legal name NetBird GmbH. This caused a reset on our software reputation.

This is a process that should take a few more days to improve as various Anti-Virus vendors re-assess their ratings, but it depends on multiple users submitting the app for analysis as false positive as well. You can do so to Windows Defender here as well as ESET here.

We've already filed the reports on our end to classify these as false-positives, but all reports help as quantity matters - so thanks for the help!

We have reported it as a false positive to Sophos. They confirmed that it is a false positive and it is no longer detected as a PUA. So Netbird users that also use Sophos should not run into issues anymore.

<!-- gh-comment-id:4387915165 --> @Geertkok1 commented on GitHub (May 6, 2026): > Hi all, > > We're definitely aware of this issue & apologize for the inconvenience caused by this. For some background information that we changed the signature on our package as the other certificate was expiring. > > With that change, we replaced the organization signing it to our legal name `NetBird GmbH`. This caused a reset on our software reputation. > > This is a process that should take a few more days to improve as various Anti-Virus vendors re-assess their ratings, but it depends on multiple users submitting the app for analysis as false positive as well. You can do so to [Windows Defender here](https://learn.microsoft.com/en-us/defender-endpoint/defender-endpoint-false-positives-negatives) as well as [ESET here](https://support.eset.com/en/kb141-submit-a-virus-website-or-potential-false-positive-sample-to-the-eset-lab). > > We've already filed the reports on our end to classify these as false-positives, but all reports help as quantity matters - so thanks for the help! We have reported it as a false positive to Sophos. They confirmed that it is a false positive and it is no longer detected as a PUA. So Netbird users that also use Sophos should not run into issues anymore.
Author
Owner

@alfrede commented on GitHub (May 7, 2026):

Could it be happens because https://bugzilla.mozilla.org/show_bug.cgi?id=2033170

<!-- gh-comment-id:4401171270 --> @alfrede commented on GitHub (May 7, 2026): Could it be happens because https://bugzilla.mozilla.org/show_bug.cgi?id=2033170
Author
Owner

@jorenminer-nexus commented on GitHub (May 17, 2026):

This is still an issue with the latest Windows Defender security definition updates, just had it flagged as a trojan on my machine after updating to the latest NetBird client.

<!-- gh-comment-id:4472136469 --> @jorenminer-nexus commented on GitHub (May 17, 2026): This is still an issue with the latest Windows Defender security definition updates, just had it flagged as a trojan on my machine after updating to the latest NetBird client.
Author
Owner

@sebastienbaillet commented on GitHub (May 17, 2026):

This is still an issue with the latest Windows Defender security definition updates, just had it flagged as a trojan on my machine after updating to the latest NetBird client.

Same here (version 0.71.2)

<!-- gh-comment-id:4472283186 --> @sebastienbaillet commented on GitHub (May 17, 2026): > This is still an issue with the latest Windows Defender security definition updates, just had it flagged as a trojan on my machine after updating to the latest NetBird client. Same here (version 0.71.2)
Author
Owner

@ben-nrth commented on GitHub (May 17, 2026):

Just had issues with Sophos detecting as a PUA when installing 0.71.2 on a new client, so this is still an issue.

<!-- gh-comment-id:4472852581 --> @ben-nrth commented on GitHub (May 17, 2026): Just had issues with Sophos detecting as a PUA when installing 0.71.2 on a new client, so this is still an issue.
Author
Owner

@kevin-dylla commented on GitHub (May 18, 2026):

Can confirm, is still happening. 0.71.2 - Manual Installation fails due to this as well

<!-- gh-comment-id:4474584764 --> @kevin-dylla commented on GitHub (May 18, 2026): Can confirm, is still happening. 0.71.2 - Manual Installation fails due to this as well
Author
Owner

@samuele-locatelli commented on GitHub (May 18, 2026):

Also here Windows Defender signals as a false positive. Maybe if a guide for reporting as a false positive on Netbird install guide could help user send notification to each antivirus provider for speed up the process...

<!-- gh-comment-id:4474850059 --> @samuele-locatelli commented on GitHub (May 18, 2026): Also here Windows Defender signals as a false positive. Maybe if a guide for reporting as a false positive on Netbird install guide could help user send notification to each antivirus provider for speed up the process...
Author
Owner

@Benjaminhu commented on GitHub (May 18, 2026):

+1 Issue confirmed (0.71.2):

installer.log "failed to start daemon: exit status 1"

2026-05-18T07:50:15.154+02:00 INFO client/cmd/update_supported.go:56: updater started: C:\Program Files\Netbird
2026-05-18T07:50:15.157+02:00 INFO client/internal/updater/installer/installer_run_windows.go:81: run exe installer: C:\ProgramData\Netbird\tmp-install\netbird_installer_0.71.2_windows_amd64.exe
2026-05-18T07:50:15.931+02:00 INFO client/internal/updater/installer/installer_run_windows.go:97: installer started with PID 16572
2026-05-18T07:50:32.447+02:00 INFO client/internal/updater/installer/installer_run_windows.go:43: starting daemon back
2026-05-18T07:50:32.447+02:00 INFO client/internal/updater/installer/installer_run_windows.go:107: starting netbird service
2026-05-18T07:50:32.574+02:00 ERRO client/internal/updater/installer/installer_run_windows.go:45: failed to start daemon: exit status 1
2026-05-18T07:50:32.575+02:00 INFO client/internal/updater/installer/installer_run_windows.go:48: starting UI back
2026-05-18T07:50:32.575+02:00 INFO client/internal/updater/installer/installer_run_windows.go:122: starting netbird-ui: C:\Program Files\Netbird\netbird-ui.exe
2026-05-18T07:50:32.588+02:00 ERRO client/internal/updater/installer/installer_run_windows.go:50: failed to start UI: failed to query user token: An attempt was made to reference a token that does not exist.
2026-05-18T07:50:32.588+02:00 INFO client/internal/updater/installer/installer_run_windows.go:53: write out result
2026-05-18T07:50:32.588+02:00 INFO client/internal/updater/installer/result.go:173: write out installer result to: C:\ProgramData\Netbird\tmp-install\result.json

result.json:

{"Success":true,"Error":"","ExecutedAt":"2026-05-18T07:50:32.5885277+02:00"}
<!-- gh-comment-id:4475304658 --> @Benjaminhu commented on GitHub (May 18, 2026): +1 Issue confirmed (0.71.2): installer.log "failed to start daemon: exit status 1" ``` 2026-05-18T07:50:15.154+02:00 INFO client/cmd/update_supported.go:56: updater started: C:\Program Files\Netbird 2026-05-18T07:50:15.157+02:00 INFO client/internal/updater/installer/installer_run_windows.go:81: run exe installer: C:\ProgramData\Netbird\tmp-install\netbird_installer_0.71.2_windows_amd64.exe 2026-05-18T07:50:15.931+02:00 INFO client/internal/updater/installer/installer_run_windows.go:97: installer started with PID 16572 2026-05-18T07:50:32.447+02:00 INFO client/internal/updater/installer/installer_run_windows.go:43: starting daemon back 2026-05-18T07:50:32.447+02:00 INFO client/internal/updater/installer/installer_run_windows.go:107: starting netbird service 2026-05-18T07:50:32.574+02:00 ERRO client/internal/updater/installer/installer_run_windows.go:45: failed to start daemon: exit status 1 2026-05-18T07:50:32.575+02:00 INFO client/internal/updater/installer/installer_run_windows.go:48: starting UI back 2026-05-18T07:50:32.575+02:00 INFO client/internal/updater/installer/installer_run_windows.go:122: starting netbird-ui: C:\Program Files\Netbird\netbird-ui.exe 2026-05-18T07:50:32.588+02:00 ERRO client/internal/updater/installer/installer_run_windows.go:50: failed to start UI: failed to query user token: An attempt was made to reference a token that does not exist. 2026-05-18T07:50:32.588+02:00 INFO client/internal/updater/installer/installer_run_windows.go:53: write out result 2026-05-18T07:50:32.588+02:00 INFO client/internal/updater/installer/result.go:173: write out installer result to: C:\ProgramData\Netbird\tmp-install\result.json ``` result.json: ``` {"Success":true,"Error":"","ExecutedAt":"2026-05-18T07:50:32.5885277+02:00"} ```
Author
Owner

@martin1ehm commented on GitHub (May 18, 2026):

+1 Confirmed with (0.71.2)
Microsoft Defender: 'Wacatac' detected on one endpoint: "Defender detected and quarantined active 'Trojan:Script/Wacatac.C!ml' in a service"

<!-- gh-comment-id:4475675199 --> @martin1ehm commented on GitHub (May 18, 2026): +1 Confirmed with (0.71.2) Microsoft Defender: 'Wacatac' detected on one endpoint: "Defender detected and quarantined active 'Trojan:Script/Wacatac.C!ml' in a service"
Author
Owner

@emrcbrn commented on GitHub (May 18, 2026):

Hi all,

It is a false positive. We are working on to remove this status from the application.

If you submit it as false positive for analysis it will help as well because having more reports will speed up the process. For Microsoft's Defender, you can do so here: https://www.microsoft.com/en-us/wdsi/filesubmission

Thank you!

<!-- gh-comment-id:4475866840 --> @emrcbrn commented on GitHub (May 18, 2026): Hi all, It is a false positive. We are working on to remove this status from the application. If you submit it as false positive for analysis it will help as well because having more reports will speed up the process. For Microsoft's Defender, you can do so here: https://www.microsoft.com/en-us/wdsi/filesubmission Thank you!
Author
Owner

@mlsmaycon commented on GitHub (May 18, 2026):

A few points to help you submit:

What do you believe this file is?
Incorrectly detected as malware/malicious
Detection name:
Trojan:Script/Wacatac.B!ml
Definition version:
1.449.675.0
Additional information *

This application has been updated recently, and as part of its auto-update, the installer removed old registry keys for the same application.
<!-- gh-comment-id:4475982141 --> @mlsmaycon commented on GitHub (May 18, 2026): A few points to help you submit: What do you believe this file is? `Incorrectly detected as malware/malicious` Detection name: `Trojan:Script/Wacatac.B!ml` Definition version: `1.449.675.0` Additional information * ``` This application has been updated recently, and as part of its auto-update, the installer removed old registry keys for the same application. ```
Author
Owner

@mlsmaycon commented on GitHub (May 18, 2026):

I got the following feedback from Microsoft:

Analyst comments:

At this time, the submitted files do not meet our criteria for malware or potentially unwanted applications. The detection has been removed. Please follow the steps below to clear cached detections and obtain the latest malware definitions.

1. Open command prompt as administrator and change directory to c:\Program Files\Windows Defender
2. Run “MpCmdRun.exe -removedefinitions -dynamicsignatures”
3. Run "MpCmdRun.exe -SignatureUpdate"

Alternatively, the latest definition is available for download here: https://docs.microsoft.com/microsoft-365/security/defender-endpoint/manage-updates-baselines-microsoft-defender-antivirus

I am marking 0.71.2 as the latest again. Thanks for your support.

<!-- gh-comment-id:4482294207 --> @mlsmaycon commented on GitHub (May 18, 2026): I got the following feedback from Microsoft: ``` Analyst comments: At this time, the submitted files do not meet our criteria for malware or potentially unwanted applications. The detection has been removed. Please follow the steps below to clear cached detections and obtain the latest malware definitions. 1. Open command prompt as administrator and change directory to c:\Program Files\Windows Defender 2. Run “MpCmdRun.exe -removedefinitions -dynamicsignatures” 3. Run "MpCmdRun.exe -SignatureUpdate" Alternatively, the latest definition is available for download here: https://docs.microsoft.com/microsoft-365/security/defender-endpoint/manage-updates-baselines-microsoft-defender-antivirus ``` I am marking 0.71.2 as the latest again. Thanks for your support.
Author
Owner

@haymesd commented on GitHub (May 18, 2026):

confirmed 0.71.2 no longer flagged by Windows Defender as of AV sigs 1.449.682.0
Thanks.

<!-- gh-comment-id:4482502052 --> @haymesd commented on GitHub (May 18, 2026): confirmed 0.71.2 no longer flagged by Windows Defender as of AV sigs 1.449.682.0 Thanks.
Author
Owner

@ObrellusRex commented on GitHub (May 19, 2026):

Automatic update works with Panda Security as well. If this tracks for the next version as well we may be able to re-enable forced automatic updates which would help a lot with maintenance tasks.

<!-- gh-comment-id:4485799662 --> @ObrellusRex commented on GitHub (May 19, 2026): Automatic update works with Panda Security as well. If this tracks for the next version as well we may be able to re-enable forced automatic updates which would help a lot with maintenance tasks.
Sign in to join this conversation.
No Label triage-needed
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#12713