UNC4841 is a China-nexus cyber espionage threat actor assessed to operate in support of the People’s Republic of China. The group is best known for long-term exploitation of Barracuda Email Security Gateway appliances through zero-day vulnerabilities, including CVE-2023-2868, to obtain persistent access across victims in multiple regions and sectors. Reporting also notes infrastructure overlap and similar tradecraft with other PRC-linked clusters, including Salt Typhoon, although this overlap has been assessed as consistent with shared infrastructure procurement or support rather than proving the same operators. UNC4841 specializes in compromising internet-facing edge devices as an initial access vector and then maintaining stealthy, durable access for intelligence collection. In Barracuda ESG intrusions, the actor deployed multiple custom malware families and components, including SALTWATER, SEASPY, SEASIDE, SEASPRAY, SKIPJACK, WHIRLPOOL, and the SANDBAR Linux rootkit. These tools provided command execution, file transfer, reverse shell access, proxying and tunneling, passive command reception through trojanized email-processing logic, and process-hiding capabilities. The actor repeatedly used defense-evasion measures such as time-stomping and rapidly modified malware components after remediation efforts to preserve access. Persistence mechanisms attributed to UNC4841 include cron jobs, startup and init-script modification, alteration of appliance scripts executed during updates or reboot, and deployment of a kernel module rootkit. The group has also been observed trojanizing legitimate Barracuda Lua modules to trigger malicious behavior from email-related events. Exfiltration activity included staging email-related data into archives and transferring it over encrypted channels, with targeted collection focused on mail stores and communications of selected users and organizations. Victimology spans public- and private-sector organizations worldwide, with confirmed targeting that includes government entities and telecommunications-related infrastructure, and reporting also places the actor in campaigns affecting satellite operators and ground systems. Observed post-compromise activity has included limited reconnaissance and scanning inside victim environments. Overall, UNC4841 is characterized by stealth, persistence, edge-device exploitation, custom malware development, and long-term intelligence collection consistent with state-sponsored espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
...UNC4841 exploited Barracuda ESG zero-day vulnerabilities... malicious email attachments to trigger remote command injection in the ESG attachment-scanning component (CVE-2023-2868)... Crafted .tar archives abused Perl’s qx operator to execute arbitrary system commands...
Barracuda later disclosed follow-on exploitation of CVE-2023-7102 in the Spreadsheet::ParseExcel library, again via malicious Excel attachments, to reinstall updated SEASPY and SALTWATER variants after initial remediation.
32 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-nexus espionage activity exploiting Barracuda Email Security Gateway (ESG) vulnerabilities (notably CVE-2023-2868 and later CVE-2023-7102) via malicious attachments to gain code execution on ESG appliances, then deploying bespoke implants (SALTWATER, SEASPY, SEASIDE) for persistence, command execution, tunneling, and exfiltration; linked to compromise of Belgium’s VSSE email flows.
China-nexus espionage activity exploiting Barracuda Email Security Gateway vulnerabilities (notably CVE-2023-2868 and later CVE-2023-7102) via malicious attachments to gain code execution on ESG appliances, then deploying bespoke implants (SALTWATER, SEASPY, SEASIDE) for persistence, command execution, tunneling, and exfiltration; linked to compromise of Belgium’s VSSE email flows.
China-nexus espionage activity exploiting Barracuda Email Security Gateway (ESG) vulnerabilities (including CVE-2023-2868 and later CVE-2023-7102) via malicious attachments to gain and maintain persistent access to email gateway infrastructure, enabling long-term collection/exfiltration (including reported compromise of Belgium’s VSSE email flows).
China-linked cluster associated with infrastructure (domains) tied to Salt Typhoon activity; details not expanded in provided content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.