SALTWATER is a Linux backdoor used in the exploitation of Barracuda Email Security Gateway appliances compromised through CVE-2023-2868, and later associated reporting also links updated variants to follow-on Barracuda exploitation activity. It is implemented as a trojanized module for the Barracuda SMTP daemon and has been attributed to activity tracked as UNC4841, a China-nexus espionage actor.
SALTWATER operates as a shared-object implant on Barracuda ESG systems and provides remote access through multiple command channels. Documented capabilities include arbitrary command execution, file upload and download, proxying, and tunneling. Technical analysis shows that it hooks network-related functions in the SMTP process, intercepts socket activity, creates worker threads, performs DNS resolution, and establishes encrypted communications over TLS. It can receive structured commands from its controller and execute shell commands with the privileges of the calling process, relay traffic, and transfer files to and from the compromised appliance.
The malware was deployed post-exploitation after attackers gained initial access to Barracuda ESG appliances via malicious email attachments that triggered remote command execution in the appliance’s attachment-processing chain. SALTWATER was one of several custom backdoors used alongside families such as SEASPY, SEASIDE, SEASPRAY, SKIPJACK, and WHIRLPOOL to maintain persistence, support espionage operations, and enable access into victim environments. Reporting on the broader campaign indicates targeting across government and private-sector organizations in multiple countries, with objectives including long-term access, email collection, and data exfiltration from affected Barracuda appliances.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The vulnerability tracked as CVE-2023-2868 (CVSS: 9.4) is a remote command injection vulnerability that impacts Barracuda ESG versions 5.1.3.001-9.2.0.006. A remote and unauthenticated threat actor may exploit the vulnerability to execute code on vulnerable assets, leading to deployment of malware and data theft. | Observed malware includes: SALTWATER, a trojanized module for the Barracuda SMTP daemon (bsmtpd) that functions as a backdoor into victim organizations; the malware is capable of file upload/download, command execution, and proxy/tunneling
Barracuda confirme l’observation des deux logiciels malveillants, SEASPY et SALTWATER, exploitant la faille critique « CVE-2023-7102 » au cours des attaques récentes, pour se faire passer pour des modules et des services Barracuda ESG légitimes. | En outre, « SALTWATER » est un module contenant des logiciels malveillants pour le démon SMTP (Simple Mail Transfer Protocol) de Barracuda (bsmtpd) qui prend en charge de nombreuses fonctionnalités telles que le téléchargement de fichiers arbitraires, l'exécution de commandes, ainsi que le proxy et le tunnelage du trafic malveillant afin d'éviter la détection.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"UNC4841 then deployed custom malware, including SALTWATER (a trojanized Simple Mail Transfer Protocol [SMTP] module enabling command execution and tunneling)..."
21 distinct techniques documented for this family, organized by ATT&CK tactic.
A remote and unauthenticated threat actor may exploit the vulnerability to execute code on vulnerable assets... A remote attacker may format file names in a specific way to enable the remote execution of system commands via Perl's qx operator.
Figures 6, 7, and 8 show the malware's capacity to connect to a remote address, and then create a new process with the command line argument '/bin/sh.'
The malware can intake data over the network, using a previously established socket, with the 'recv' function... using 'popen', the malware can execute any shell command with the same privileges as its calling process.
SEASPY est un backdoor persistant x64 qui se fait passer pour un service légitime de Barracuda Networks ... En outre, « SALTWATER » est un module contenant des logiciels malveillants pour le démon SMTP ...
Figure 12 shows the malware creating a new thread, within the calling process. This is thread injection and it can inject two different functions.
Figures 14 and 15 show the second function. The second function can establish communications, over the network, using a TLS version 1 connection.
“SALTWATER (a trojanized SMTP module enabling command execution and tunneling)… SEASIDE… turns SMTP HELO/EHLO data into reverse shells”
Figure 10 shows the malware's capacity to perform DNS resolution, using the system call 'sys_getpeername.' ... Figure 13 shows the first function that can perform DNS resolution.
SALTWATER... functions as a backdoor into victim organizations; the malware is capable of file upload/download, command execution, and proxy/tunneling
SALTWATER... is capable of file upload/download, command execution, and proxy/tunneling
Once access was achieved, both novel and known customized malware were deployed to victim organizations. Observed malware includes: SALTWATER... capable of file upload/download
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojanized SMTP module used on compromised Barracuda ESG appliances to enable command execution and tunneling (persistence/access and likely exfiltration support).
Custom implant described as a trojanized SMTP module on Barracuda ESG that enables command execution and tunneling, supporting persistence and data exfiltration from compromised email security gateways.
Custom implant for Barracuda ESG: a trojanized SMTP module used for command execution and tunneling, turning the email security gateway into a persistent access/exfiltration node.
SALTWATER is a backdoor malware deployed by Chinese APT UNC4841 after exploiting a zero-day in Barracuda Email Security Gateway appliances, used to maintain persistent access and facilitate espionage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.