SEASPY is a persistent, passive Linux backdoor used in espionage activity targeting Barracuda Email Security Gateway appliances. It is closely associated with exploitation of CVE-2023-2868, a remote command injection vulnerability in Barracuda ESG, and later reporting also links updated SEASPY variants to exploitation of CVE-2023-7102. The malware masquerades as a legitimate Barracuda service, commonly using the service name BarracudaMailService, to blend into the appliance environment and survive remediation efforts.
SEASPY operates as a packet-triggered backdoor. It uses packet-capture functionality to monitor SMTP-related traffic, specifically watching for specially crafted trigger packets on mail ports. When the expected trigger sequence is observed, it initiates a reverse shell to attacker-controlled infrastructure, enabling arbitrary command execution on the compromised appliance. This design allows the implant to remain dormant and difficult to detect until activated. Analysis has also assessed SEASPY as being based on the open-source backdoor cd00r.
The malware was deployed post-exploitation by the China-nexus espionage cluster UNC4841 as part of a broader Barracuda ESG intrusion set that also included SALTWATER, SEASIDE, WHIRLPOOL, SEASPRAY, SKIPJACK, SUBMARINE, and SANDBAR. UNC4841 modified SEASPY during incident response and patching efforts, repeatedly re-established persistence, and in some cases ensured execution on reboot through startup-script changes. SEASPY was also used alongside other tooling intended to maintain long-term access, support follow-on operations, and evade detection.
Targeting centered on Barracuda ESG appliances deployed across government and private-sector organizations worldwide. The broader campaign has been linked to long-term access, email-focused espionage, credential and certificate theft from appliances, limited internal reconnaissance, and data exfiltration. SEASPY’s role within this ecosystem was to provide covert, durable remote access on compromised Linux-based email security appliances.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The vulnerability tracked as CVE-2023-2868 (CVSS: 9.4) is a remote command injection vulnerability that impacts Barracuda ESG versions 5.1.3.001-9.2.0.006. A remote and unauthenticated threat actor may exploit the vulnerability to execute code on vulnerable assets, leading to deployment of malware and data theft. | SEASPY, a second backdoor malware that impersonates Barracuda Network service and “establishes itself as a PCAP filter, specifically monitoring traffic on port 25”
Barracuda confirme l’observation des deux logiciels malveillants, SEASPY et SALTWATER, exploitant la faille critique « CVE-2023-7102 » au cours des attaques récentes, pour se faire passer pour des modules et des services Barracuda ESG légitimes. | Barracuda confirme l’observation des deux logiciels malveillants, SEASPY et SALTWATER, exploitant la faille critique « CVE-2023-7102 » au cours des attaques récentes, pour se faire passer pour des modules et des services Barracuda ESG légitimes. Il est à noter que « SEASPY » est un backdoor persistant x64 qui se fait passer pour un service légitime de Barracuda Networks et se fait passer pour un filtre PCAP, surveillant spécifiquement le trafic sur le port 25.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...SEASPY (a backdoor masquerading as BarracudaMailService triggered by “magic packets”)..."
23 distinct techniques documented for this family, organized by ATT&CK tactic.
“execution of their initial reverse shell via hourly and daily cron jobs… /etc/cron.hourly/… /etc/cron.daily/…”
A remote and unauthenticated threat actor may exploit the vulnerability to execute code on vulnerable assets... A remote attacker may format file names in a specific way to enable the remote execution of system commands via Perl's qx operator.
“persistently executed SEASPY on appliance reboot through…addition to /etc/init.d/rc…”
“execution of their initial reverse shell via hourly and daily cron jobs… /etc/cron.hourly/… /etc/cron.daily/…”
SEASPY prend également en charge une fonctionnalité de backdoor activé par un "magic packet"
SEASPY is a persistent and passive backdoor that masquerades as a legitimate Barracuda service.
“persistently executed SEASPY on appliance reboot through…addition to /etc/init.d/rc…”
“execution of their initial reverse shell via hourly and daily cron jobs… /etc/cron.hourly/… /etc/cron.daily/…”
SEASPY, a second backdoor malware that impersonates Barracuda Network service
“UNC4841 has repeatedly utilized time-stomping to further hide their malicious activity.”
SALTWATER is a backdoor that can perform DNS resolution and establish communications, over the network, using a TLS version 1 connection.
“SALTWATER (a trojanized SMTP module enabling command execution and tunneling)… SEASIDE… turns SMTP HELO/EHLO data into reverse shells”
These backdoors functioned by capturing the SMTP traffic, proxying into victim environments and maintaining persistence.
Once access was achieved, both novel and known customized malware were deployed to victim organizations. Observed malware includes: SALTWATER... capable of file upload/download
38 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor described as magic-packet malware targeting Barracuda Networks Email Security Gateway appliances.
Backdoor implant on Barracuda ESG appliances that masquerades as a legitimate service and is activated via specially crafted network traffic (“magic packets”).
Custom backdoor used on Barracuda ESG; masquerades as a legitimate service and is triggered via specially crafted network traffic (“magic packets”) to provide covert access.
Custom backdoor used on Barracuda ESG appliances; masquerades as a legitimate service and is activated via specially crafted network traffic (“magic packets”) to maintain covert persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.