SEASPY is a persistent backdoor used in espionage operations targeting Barracuda Email Security Gateway appliances. It has been associated with the China-nexus cluster UNC4841 and was deployed alongside other Barracuda-focused malware families including SALTWATER and SEASIDE following exploitation of Barracuda ESG vulnerabilities such as CVE-2023-2868, and later in follow-on exploitation involving CVE-2023-7102. The malware masquerades as a legitimate Barracuda service and has been described as a 64-bit implant that can survive appliance reboots through modified startup mechanisms and other persistence changes on compromised systems.
Operational reporting indicates SEASPY was used to maintain long-term access on Barracuda ESG devices, including in campaigns affecting government and private-sector organizations across multiple countries. It has been characterized as a backdoor triggered by specially crafted network traffic or "magic packets," and as part of a broader intrusion set focused on covert access, persistence, and collection from email security infrastructure. In these intrusions, associated malware and operator activity included monitoring SMTP traffic, maintaining footholds on the appliance, staging and exfiltrating email-related data, stealing certificates, and in some cases conducting limited internal reconnaissance and proxying into victim environments.
SEASPY’s role in the UNC4841 toolchain was post-compromise persistence and covert remote access on Barracuda ESG appliances rather than commodity distribution. The malware’s use of service masquerading, stealthy activation, and persistence on reboot made it suitable for prolonged espionage against organizations whose email gateways handled sensitive diplomatic, governmental, and enterprise communications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Barracuda disclosed that a zero-day vulnerability (CVE-2023-2868) in the Barracuda Email Security Gateway (ESG) had been exploited in the wild as early as October 2022 and remained undiscovered until May 2023. | From the observation, three principle backdoors has been used to be deployed using this vulnerability namely SALTWATER, SEASIDE and SEASPY... Additional post exploitation malware has been deployed to maintain persistence in the victim environment namely SEASPY v2, WHIRPOOL, SEASPRAY.
Barracuda confirme l’observation des deux logiciels malveillants, SEASPY et SALTWATER, exploitant la faille critique « CVE-2023-7102 » au cours des attaques récentes, pour se faire passer pour des modules et des services Barracuda ESG légitimes. | Barracuda confirme l’observation des deux logiciels malveillants, SEASPY et SALTWATER, exploitant la faille critique « CVE-2023-7102 » au cours des attaques récentes, pour se faire passer pour des modules et des services Barracuda ESG légitimes. Il est à noter que « SEASPY » est un backdoor persistant x64 qui se fait passer pour un service légitime de Barracuda Networks et se fait passer pour un filtre PCAP, surveillant spécifiquement le trafic sur le port 25.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...SEASPY (a backdoor masquerading as BarracudaMailService triggered by “magic packets”)..."
19 distinct techniques documented for this family, organized by ATT&CK tactic.
“execution of their initial reverse shell via hourly and daily cron jobs… /etc/cron.hourly/… /etc/cron.daily/…”
This can be exploited by an email attachment that results in execution of a reverse shell payload into the affected product.
“persistently executed SEASPY on appliance reboot through…addition to /etc/init.d/rc…”
“execution of their initial reverse shell via hourly and daily cron jobs… /etc/cron.hourly/… /etc/cron.daily/…”
SEASPY est un backdoor persistant x64 qui se fait passer pour un service légitime de Barracuda Networks ... En outre, « SALTWATER » est un module contenant des logiciels malveillants pour le démon SMTP ...
“UNC4841 has repeatedly utilized time-stomping to further hide their malicious activity.”
“SALTWATER (a trojanized SMTP module enabling command execution and tunneling)… SEASIDE… turns SMTP HELO/EHLO data into reverse shells”
These backdoors functioned by capturing the SMTP traffic, proxying into victim environments and maintaining persistence.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor described as magic-packet malware targeting Barracuda Networks Email Security Gateway appliances.
Backdoor implant on Barracuda ESG appliances that masquerades as a legitimate service and is activated via specially crafted network traffic (“magic packets”).
Custom backdoor used on Barracuda ESG; masquerades as a legitimate service and is triggered via specially crafted network traffic (“magic packets”) to provide covert access.
Custom backdoor used on Barracuda ESG appliances; masquerades as a legitimate service and is activated via specially crafted network traffic (“magic packets”) to maintain covert persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.