Bitdefender marks netbird.exe as cryptomining app #1165

Open
opened 2025-11-20 05:25:09 -05:00 by saavagebueno · 10 comments
Owner

Originally created by @tomashora on GitHub (Aug 20, 2024).

Describe the problem

Bitdefender thinks that netbird.exe is trying to mine crypto. Threat name: Gen:Miner.Kenari.BitcoinCore.@N2@bGtE44
This happens firs time when the installation proces executes netbird service install but Bitdefender detects cryptomining activity at all netbird commands (netbird status, atc...).

This does not happen when installing previous versions - tested on 0.28.7 without being marked as crypto mine on the same Bitdefender definitions.

Bitdefender definitions in screenshot below.

To Reproduce

Steps to reproduce the behavior:

  1. Install Bitdefender Total Security
  2. Install Netbird 0.28.8
  3. Bitdefender automatically puts netbird.exe into Quarantine

Expected behavior

Netbird is installed correctly withtout being marked as a security threat

Are you using NetBird Cloud?

Unrelated - self-hosted

NetBird version

0.28.8

NetBird status -dA output:

N/A

Do you face any (non-mobile) client issues?

N/A

Screenshots
image

image

Additional context

N/A

Originally created by @tomashora on GitHub (Aug 20, 2024). **Describe the problem** Bitdefender thinks that netbird.exe is trying to mine crypto. Threat name: Gen:Miner.Kenari.BitcoinCore.@N2@bGtE44 This happens firs time when the installation proces executes `netbird service install` but Bitdefender detects cryptomining activity at all netbird commands (netbird status, atc...). This does not happen when installing previous versions - tested on 0.28.7 without being marked as crypto mine on the same Bitdefender definitions. Bitdefender definitions in screenshot below. **To Reproduce** Steps to reproduce the behavior: 1. Install Bitdefender Total Security 2. Install Netbird 0.28.8 3. Bitdefender automatically puts netbird.exe into Quarantine **Expected behavior** Netbird is installed correctly withtout being marked as a security threat **Are you using NetBird Cloud?** Unrelated - self-hosted **NetBird version** 0.28.8 **NetBird status -dA output:** N/A **Do you face any (non-mobile) client issues?** N/A **Screenshots** ![image](https://github.com/user-attachments/assets/4810cde0-c3a0-449c-b42e-df4cfdab6716) ![image](https://github.com/user-attachments/assets/a27f441f-4857-4a80-88f7-fae7f465df9c) **Additional context** N/A
saavagebueno added the triage-needed label 2025-11-20 05:25:09 -05:00
Author
Owner

@tomashora commented on GitHub (Aug 21, 2024):

Reported to Bitdefender Malware Lab as well and should have reply within 72hours.

@tomashora commented on GitHub (Aug 21, 2024): Reported to Bitdefender Malware Lab as well and should have reply within 72hours.
Author
Owner

@mlsmaycon commented on GitHub (Aug 21, 2024):

Thanks for reporting this, @tomashora. We will look into Bitdefender white listing the programs so that we can always push our binaries for analysis.

@mlsmaycon commented on GitHub (Aug 21, 2024): Thanks for reporting this, @tomashora. We will look into Bitdefender white listing the programs so that we can always push our binaries for analysis.
Author
Owner

@lymington commented on GitHub (Aug 28, 2024):

New user - trying to download connector for Windows - Bitdefender still blocking (despite adding as exception) - 0.28.9

@lymington commented on GitHub (Aug 28, 2024): New user - trying to download connector for Windows - Bitdefender still blocking (despite adding as exception) - 0.28.9
Author
Owner

@tomashora commented on GitHub (Aug 29, 2024):

@lymington Set the cryptomining protection to only detect activities

@tomashora commented on GitHub (Aug 29, 2024): @lymington Set the cryptomining protection to only detect activities
Author
Owner

@mlsmaycon commented on GitHub (Aug 29, 2024):

@tomashora we still got no response from Bitdefender on the partner program. Did you received anything from them on your submission?

@mlsmaycon commented on GitHub (Aug 29, 2024): @tomashora we still got no response from Bitdefender on the partner program. Did you received anything from them on your submission?
Author
Owner

@tomashora commented on GitHub (Aug 29, 2024):

@tomashora we still got no response from Bitdefender on the partner program. Did you received anything from them on your submission?

@mlsmaycon they did not react on the first message so I asked them again and got response from then 2 days ago that they sent it to Malware Research Team for analysis purposes and will let me know once it's done.

I will post a comment to this issue once I have more information.

@tomashora commented on GitHub (Aug 29, 2024): > @tomashora we still got no response from Bitdefender on the partner program. Did you received anything from them on your submission? @mlsmaycon they did not react on the first message so I asked them again and got response from then 2 days ago that they sent it to Malware Research Team for analysis purposes and will let me know once it's done. I will post a comment to this issue once I have more information.
Author
Owner

@mlsmaycon commented on GitHub (Aug 29, 2024):

Thanks for the update

@mlsmaycon commented on GitHub (Aug 29, 2024): Thanks for the update
Author
Owner

@tomashora commented on GitHub (Aug 31, 2024):

Today's update from Bitdefender support:

Our Malware Research Team has finished analyzing your case.

The file is clean and detection should be removed in the next couple of updates.

@tomashora commented on GitHub (Aug 31, 2024): Today's update from Bitdefender support: Our Malware Research Team has finished analyzing your case. The file is clean and detection should be removed in the next couple of updates.
Author
Owner

@tomashora commented on GitHub (Sep 9, 2024):

Seems to be fixed after updating netbird to 0.29.0. Bitdefender has not yet fixed the issue with netbird version 0.28.8

@tomashora commented on GitHub (Sep 9, 2024): Seems to be fixed after updating netbird to 0.29.0. Bitdefender has not yet fixed the issue with netbird version 0.28.8
Author
Owner

@tomashora commented on GitHub (Nov 14, 2025):

@mlsmaycon It was ok until now, but with netbird 0.59.13 the issue is back causing the installation to fail because Bitdefender removes the file. Reported to Bitdefender, but not much will happen there...

Image
@tomashora commented on GitHub (Nov 14, 2025): @mlsmaycon It was ok until now, but with netbird 0.59.13 the issue is back causing the installation to fail because Bitdefender removes the file. Reported to Bitdefender, but not much will happen there... <img width="724" height="250" alt="Image" src="https://github.com/user-attachments/assets/fdef56b5-def0-4bc9-8f9e-b6f75d6d0c00" />
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: SVI/netbird#1165