SUBMARINE is a novel Linux backdoor used in compromises of Barracuda Email Security Gateway appliances following exploitation of CVE-2023-2868. It is designed for root-level, persistent access and resides in the appliance’s SQL database, where a malicious trigger initiates a multi-stage infection chain. The malware uses database-resident logic, shell scripts, and a preloaded shared library to achieve execution, persistence, command handling, and cleanup on the compromised appliance.
The infection chain includes a malicious SQL trigger that executes as root, writes and launches an encoded archive, and invokes shell logic that prepares additional components. A loader script then relocates components into persistent storage, modifies appliance startup or service-control behavior, and ensures repeated execution through a persistence helper script. A maliciously altered service-control script preloads the final payload into the Barracuda SMTP daemon through LD_PRELOAD.
The final payload is a Linux shared object that runs inside the SMTP-related process context. It can receive data locally, decode base64 content, decrypt commands using AES-256-CBC, and pass the resulting instructions to the shell for execution. The malware also performs cleanup actions to remove traces from mail-processing locations. Its architecture and root execution model make it suitable for durable post-compromise access and follow-on operations on affected Barracuda ESG systems.
SUBMARINE has been associated with broader malicious activity against Barracuda ESG appliances in which multiple backdoors were deployed, including SEASPRAY, WHIRLPOOL, SKIPJACK, and SALTWATER. It has been assessed as a serious persistence mechanism and a significant enabler of further intrusion activity on compromised email security infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The malware was used by threat actors exploiting CVE-2023-2868, a former zero-day vulnerability affecting certain versions 5.1.3.001 - 9.2.0.006 of Barracuda Email Security Gateway (ESG). | CISA obtained seven malware samples related to a novel backdoor CISA has named SUBMARINE. The malware was used by threat actors exploiting CVE-2023-2868... SUBMARINE is a novel persistent backdoor that lives in a Structured Query Language (SQL) database on the ESG appliance.
16 distinct techniques documented for this family, organized by ATT&CK tactic.
SUBMARINE comprises multiple artifacts—including a SQL trigger, shell scripts, and a loaded library for a Linux daemon—that together enable execution with root privileges, persistence, command and control, and cleanup.
The 'sed' command is used with a '-i' flag to modify the file 'update_version' within the '/boot/os_tools/' directory with an appended string to line 44. The appended string, "system('/boot/os_tools/hw-set 2>&1 >/dev/null &');", will run the file 'hw-set' in the background whenever the file 'update_version' is executed.
The name of the file is designed to exploit a vulnerability on the target environment where the base64 string within the file name will be executed on the Linux shell.
The commands will decode the base64 encoded string and execute the decoded result as a shell command... Then, the file 'run.sh' executes with the 'nohup' parameter.
SUBMARINE comprises multiple artifacts—including a SQL trigger, shell scripts, and a loaded library for a Linux daemon—that together enable execution with root privileges, persistence, command and control, and cleanup.
The 'sed' command is used with a '-i' flag to modify the file 'update_version' within the '/boot/os_tools/' directory with an appended string to line 44. The appended string, "system('/boot/os_tools/hw-set 2>&1 >/dev/null &');", will run the file 'hw-set' in the background whenever the file 'update_version' is executed.
SUBMARINE comprises multiple artifacts—including a SQL trigger, shell scripts, and a loaded library for a Linux daemon—that together enable execution with root privileges, persistence, command and control, and cleanup.
The 'sed' command is used with a '-i' flag to modify the file 'update_version' within the '/boot/os_tools/' directory with an appended string to line 44. The appended string, "system('/boot/os_tools/hw-set 2>&1 >/dev/null &');", will run the file 'hw-set' in the background whenever the file 'update_version' is executed.
The file is a Base64 encoded GNU Zip (GZIP) archive... The file contains base64 encoded commands... accepts input '%s', decodes it with Base64, decrypts it with AES...
The file name is designed to exploit a vulnerability on the target environment where the base64 string within the file name will be executed on the Linux shell.
SALTWATER is a backdoor that can perform DNS resolution and establish communications, over the network, using a TLS version 1 connection.
The file 'libutil.so' is preloaded into the BSMTP daemon... Therefore, given this information, the malware has the capacity to accept encoded and encrypted inputs from 'bsmtpd', execute them, and print a message.
33 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.