SALTWATER is a backdoor used by the China-nexus espionage cluster UNC4841 in the exploitation of Barracuda Email Security Gateway appliances, notably through CVE-2023-2868 and later follow-on exploitation associated with CVE-2023-7102. It is implemented as a trojanized module for the Barracuda SMTP daemon and was deployed alongside other Barracuda-focused malware families including SEASPY and SEASIDE to establish long-term access on compromised appliances.
The malware provides remote command execution, arbitrary file upload and download, proxying, and traffic tunneling. Its implementation hooks network-related functions in the SMTP daemon to intercept socket activity and support covert command-and-control operations. SALTWATER communicates with attacker infrastructure over encrypted channels and supports multiple functional channels for shell execution, file transfer, proxy relay, and tunnel configuration. These capabilities enabled operators to maintain access, move traffic through victim appliances, and support broader espionage operations.
SALTWATER targeted Barracuda ESG appliances running the Barracuda SMTP service and formed part of a wider post-compromise ecosystem used to capture SMTP traffic, facilitate persistence, and enable data theft from victim environments. UNC4841 was observed modifying SALTWATER components during remediation efforts, including time-stomping and rapid retooling to preserve access. Victim organizations spanned government and private-sector entities across multiple countries, with activity consistent with intelligence collection and long-term network access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Barracuda disclosed that a zero-day vulnerability (CVE-2023-2868) in the Barracuda Email Security Gateway (ESG) had been exploited in the wild as early as October 2022 and remained undiscovered until May 2023. | From the observation, three principle backdoors has been used to be deployed using this vulnerability namely SALTWATER, SEASIDE and SEASPY.
Barracuda confirme l’observation des deux logiciels malveillants, SEASPY et SALTWATER, exploitant la faille critique « CVE-2023-7102 » au cours des attaques récentes, pour se faire passer pour des modules et des services Barracuda ESG légitimes. | En outre, « SALTWATER » est un module contenant des logiciels malveillants pour le démon SMTP (Simple Mail Transfer Protocol) de Barracuda (bsmtpd) qui prend en charge de nombreuses fonctionnalités telles que le téléchargement de fichiers arbitraires, l'exécution de commandes, ainsi que le proxy et le tunnelage du trafic malveillant afin d'éviter la détection.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"UNC4841 then deployed custom malware, including SALTWATER (a trojanized Simple Mail Transfer Protocol [SMTP] module enabling command execution and tunneling)..."
16 distinct techniques documented for this family, organized by ATT&CK tactic.
This can be exploited by an email attachment that results in execution of a reverse shell payload into the affected product.
a remote attacker can construct these file names specially in a way that will enable remote system command execution using Perl's qx operator with the privileges of the Email Security Gateway product.
SEASPY est un backdoor persistant x64 qui se fait passer pour un service légitime de Barracuda Networks ... En outre, « SALTWATER » est un module contenant des logiciels malveillants pour le démon SMTP ...
“SALTWATER (a trojanized SMTP module enabling command execution and tunneling)… SEASIDE… turns SMTP HELO/EHLO data into reverse shells”
These backdoors functioned by capturing the SMTP traffic, proxying into victim environments and maintaining persistence.
From the observation, three principle backdoors has been used to be deployed using this vulnerability namely SALTWATER, SEASIDE and SEASPY.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojanized SMTP module used on compromised Barracuda ESG appliances to enable command execution and tunneling (persistence/access and likely exfiltration support).
Custom implant described as a trojanized SMTP module on Barracuda ESG that enables command execution and tunneling, supporting persistence and data exfiltration from compromised email security gateways.
Custom implant for Barracuda ESG: a trojanized SMTP module used for command execution and tunneling, turning the email security gateway into a persistent access/exfiltration node.
SALTWATER is a backdoor malware deployed by Chinese APT UNC4841 after exploiting a zero-day in Barracuda Email Security Gateway appliances, used to maintain persistent access and facilitate espionage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.