SEASIDE is a Lua-based backdoor module used by the China-nexus espionage actor UNC4841 in the compromise of Barracuda Email Security Gateway appliances through CVE-2023-2868. It is implemented as a module for the Barracuda SMTP daemon and is designed to monitor SMTP HELO and EHLO commands for specially encoded command-and-control information. After decoding a supplied address and port from SMTP traffic, SEASIDE passes those parameters to the companion utility WHIRLPOOL, which establishes a reverse shell from the compromised appliance.
SEASIDE formed part of a broader post-exploitation toolkit that also included SALTWATER, SEASPY, SEASPRAY, SKIPJACK, WHIRLPOOL, and the SANDBAR rootkit. In observed intrusions, these payloads were deployed after exploitation of Barracuda ESG attachment-processing flaws via malicious email attachments, enabling long-term persistence, covert access, and espionage operations. UNC4841 used the Barracuda appliance foothold to maintain access for extended periods, capture SMTP-related data, proxy into victim environments, and support data theft from email-processing components. The actor also employed anti-forensic measures such as time-stomping and rapid component replacement during remediation efforts.
SEASIDE targets Barracuda ESG appliances running a Linux-based environment and is notable for abusing normal SMTP protocol handling as a covert trigger channel for reverse-shell activation. Its role in the intrusion set is post-compromise remote access rather than initial exploitation, and its use has been associated with government and private-sector victims across multiple countries.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The vulnerability tracked as CVE-2023-2868 (CVSS: 9.4) is a remote command injection vulnerability that impacts Barracuda ESG versions 5.1.3.001-9.2.0.006. A remote and unauthenticated threat actor may exploit the vulnerability to execute code on vulnerable assets, leading to deployment of malware and data theft. | SEASIDE, a Lua-based module used to establish a reverse shell on compromised assets
"...and SEASIDE (a Lua module that turns SMTP HELO/EHLO data into reverse shells)..."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...and SEASIDE (a Lua module that turns SMTP HELO/EHLO data into reverse shells)..."
11 distinct techniques documented for this family, organized by ATT&CK tactic.
A remote and unauthenticated threat actor may exploit the vulnerability to execute code on vulnerable assets... A remote attacker may format file names in a specific way to enable the remote execution of system commands via Perl's qx operator. | SEASIDE, a Lua-based module used to establish a reverse shell on compromised assets
“SALTWATER (a trojanized SMTP module enabling command execution and tunneling)… SEASIDE… turns SMTP HELO/EHLO data into reverse shells”
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lua-based implant/module on Barracuda ESG that converts SMTP protocol fields (HELO/EHLO) into a command channel enabling reverse shells.
Lua-based implant/module on Barracuda ESG that abuses SMTP protocol fields (HELO/EHLO) to trigger reverse shells, enabling remote access and command execution.
Lua-based implant/module on Barracuda ESG that abuses SMTP protocol fields (HELO/EHLO) to trigger reverse shells, enabling remote command execution and persistence.
SEASIDE is a backdoor malware deployed by Chinese APT UNC4841 on Barracuda ESG appliances, enabling persistent access and data exfiltration after exploitation of a zero-day vulnerability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.