Barracuda confirms that a China-nexus threat actor (UNC4841) exploited an Arbitrary Code Execution vulnerability in a third-party library to deploy backdoors on ESG appliances, with patches and remediation guidance issued. The campaign involved new SEASPY and SALTWATER variants and ongoing investigation alongside Mandiant; Barracuda also provided replacement appliances to impacted customers. #UNC4841 #SALTWATER #SEASPY #SEASIDE #CVE-2023-2868 #BarracudaESG #Mandiant
Keypoints
- UNC4841 is linked to the ESG incident, described as a high-confidence attribution by Barracuda and Mandiant.
- The attack leveraged an ACE vulnerability in Spreadsheet::ParseExcel (CVE-2023-7102) and a separate ACE in the same library (CVE-2023-7101) to deploy malicious payloads via crafted attachments, prompting automatic security updates.
- New malware families (SEASPY and SALTWATER) were observed on a limited number of ESG devices after exploitation.
- Barracuda recommended immediate replacement of compromised ESG appliances; replacements were provided at no cost.
- Mandiant analyzed related activity and referenced SUBMARINE in conjunction with CISA’s analyses to describe persistence actions taken by threat actors.
- Comprehensive IOCs (files, domains, IPs) and YARA rules were published to aid customers in detecting and hunting for related activity.
MITRE Techniques
- [T1190] Exploit Public-Facing Application – Used to gain unauthorized access to ESG appliances via the ACE vulnerability in Spreadsheet::ParseExcel; “…remotely executing a system command through Perl’s qx operator…”
- [T1059] Command and Scripting Interpreter – Attack leveraged Perl’s qx operator to execute system commands on the appliance.
- [T1105] Ingress Tool Transfer – SALTWATER/S SEASPY backdoors include channels for downloading/uploading modules (DownloadChannel, UploadChannel, etc.).
- [T1036] Masquerading – SEASPY variant “poses as a legitimate Barracuda Networks service” to persist on the device.
- [T1041] Exfiltration – Evidence of data exfiltration identified on impacted appliances.
- [T1027] Obfuscated/Compressed Files and Information – YARA and indicators reference base64-encoded content within TAR archives used in the exploit chain.
- [T1043] config/command and control channels (SEASIDE) – SEASIDE monitors SMTP HELO/EHLO commands to obtain C2 address/port and spawn a reverse shell.
Indicators of Compromise
- [File Hash] CVE-2023-7102 XLS Document – 2b172fe3329260611a9022e71acdebca, 803cb5a7de1fe0067a9eeb220dfc24ca56f3f571a986180e146b6cf387855bdd
- [File Hash] SALTWATER variant (mod_udp.so) – 827d507aa3bde0ef903ca5dec60cdec8
- [File Name] XLS attachments – ads2.xls, don.xls, personalbudget.xls
- [File Type] xls, x-executable
- [Network IP] 23.224.99.242, 23.224.99.243
- [Network IP] 23.224.99.244, 23.224.99.245
- [Domain] bestfindthetruth.com, fessionalwork.com
- [Domain] gesturefavour.com, goldenunder.com
- [Endpoint File] snapshot.tar, install_reuse.tar, imgdata.jpg
- [Network IP] 64.176.7.59, 64.176.4.234
- [Network IP] mx01.bestfindthetruth.com (and 2 more domains in Table 5)
Read more: https://www.barracuda.com/company/legal/esg-vulnerability