SEASIDE is a Lua-based backdoor module used by the China-nexus espionage cluster UNC4841 in compromises of Barracuda Email Security Gateway appliances. It was deployed during exploitation of the Barracuda ESG zero-day CVE-2023-2868 and formed part of a broader post-compromise toolkit that also included SALTWATER, SEASPY, WHIRLPOOL, SEASPRAY, SKIPJACK, and the SANDBAR rootkit.
SEASIDE operates as a trojanized module for the Barracuda SMTP daemon. It monitors SMTP HELO and EHLO commands for specially encoded command-and-control information, decodes an IP address and port from that traffic, and passes the decoded values to WHIRLPOOL, an external utility that establishes a TLS reverse shell. This design allows command-and-control signaling to be embedded in normal SMTP protocol exchanges while delegating interactive access to a separate reverse-shell component.
The malware was used to establish and maintain access on Barracuda ESG appliances for extended periods and was associated with broader espionage activity against government and private-sector organizations worldwide. UNC4841 used the Barracuda compromises to maintain persistence, proxy into victim environments, capture SMTP traffic, and support data theft operations, including exfiltration of email-related data and SSL certificates from affected appliances. Reporting also notes the actor used time-stomping and other anti-forensic measures during deployment and maintenance of related tooling.
SEASIDE targets Barracuda ESG appliances, which run on Linux-based systems, and is best characterized as a backdoor component enabling covert remote access after initial exploitation via malicious email attachments that triggered remote command execution on the appliance.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Barracuda disclosed that a zero-day vulnerability (CVE-2023-2868) in the Barracuda Email Security Gateway (ESG) had been exploited in the wild as early as October 2022 and remained undiscovered until May 2023. | From the observation, three principle backdoors has been used to be deployed using this vulnerability namely SALTWATER, SEASIDE and SEASPY.
"...and SEASIDE (a Lua module that turns SMTP HELO/EHLO data into reverse shells)..."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...and SEASIDE (a Lua module that turns SMTP HELO/EHLO data into reverse shells)..."
11 distinct techniques documented for this family, organized by ATT&CK tactic.
This can be exploited by an email attachment that results in execution of a reverse shell payload into the affected product.
“SALTWATER (a trojanized SMTP module enabling command execution and tunneling)… SEASIDE… turns SMTP HELO/EHLO data into reverse shells”
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lua-based implant/module on Barracuda ESG that converts SMTP protocol fields (HELO/EHLO) into a command channel enabling reverse shells.
Lua-based implant/module on Barracuda ESG that abuses SMTP protocol fields (HELO/EHLO) to trigger reverse shells, enabling remote access and command execution.
Lua-based implant/module on Barracuda ESG that abuses SMTP protocol fields (HELO/EHLO) to trigger reverse shells, enabling remote command execution and persistence.
SEASIDE is a backdoor malware deployed by Chinese APT UNC4841 on Barracuda ESG appliances, enabling persistent access and data exfiltration after exploitation of a zero-day vulnerability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.