Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors barracuda

Also known as: UNC4841, tracked as, the Seapike, APT44, sectors, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, whitelist, Royal Ransomware

Description

Barracuda—also known as UNC4841 or APT44—has been active since mid‑2022 targeting a wide spectrum of sectors including government, finance, healthcare, and critical infrastructure. The group’s primary motivation is financial gain, achieved through ransomware, data theft, and extortion campaigns. Their operations are characterized by sophisticated social engineering via phishing emails that deliver specially crafted TAR files, which exploit the CVE-2023‑2868 vulnerability in Barracuda ESG appliances to achieve remote code execution. Once compromised, attackers use the appliance’s SMTP functionality to move laterally across an organization by sending further malicious payloads from the infected device. They install multiple backdoor modules—SALTWATER, SEASPY, and SEASIDE—which integrate as Trojanized Lua modules or PCAP filters to maintain persistence and provide covert exfiltration channels through web services and alternative protocols. The actors occasionally deploy ransomware, most notably Royal Ransomware, to extort victims after securing data for sale or leverage. The group's geographic focus is broad, with documented attacks in China, the United Kingdom, Taiwan, India, Ukraine, Russia, the US, Germany, Korea, Iran, Azerbaijan, Pakistan, Belarus, Poland, Canada, and Australia. Despite being labeled a “criminal” threat actor, Barracuda’s methods reflect a sophisticated state‑sponsored or at least well‑equipped operation with capabilities mirroring those seen in China‑linked espionage campaigns.

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Government
Financial services
Education
Healthcare
Telecommunications
Defense
Critical infrastructure
Manufacturing
Media
Retail
Non profit
Information technology
Hospitality
Mining
Energy
Aerospace
Maritime
Nuclear
Entertainment
Gaming
Food agriculture
Construction
Transportation

Targeted Countries / Regions

CN
GB
TW
IN
UA
RU
US
DE
KP
IR
AZ
PK
BY
PL
CA
AU

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 15 hours ago

Executive Summary

Barracuda is a medium‑sophistication cybercriminal group that leveraged the CVE-2023-2868 remote command injection flaw in Barracuda Email Security Gateway appliances using malicious TAR attachments from October 2022 to May 2023. The actors deployed a suite of backdoors (SALTWATER, SEASPY, SEASIDE) for persistence and data exfiltration, later injecting ransomware such as Royal Ransomware to extort victims.

Goals & Targeting

Barracuda seeks to compromise high‑value infrastructure across diverse industries, primarily to exfiltrate data for monetary gain and later to ransom victims. Their multi‑stage approach—initial exploitation of a critical vendor vulnerability, followed by backdoor persistence, lateral movement via SMTP, covert exfiltration, and optional ransomware payloads—suggests an agenda that combines both commercial espionage and financial extortion. The broad victim set points toward opportunistic targeting rather than narrowly focused political objectives. key_capabilities":["Exploits CVE-2023-2868 via malicious TAR attachments","Uses phishing emails with disguised or spoofed attachments to deliver payloads","Deploys specialized backdoor families such as SALTWATER, SEASPY, and SEASIDE","Permanently persists by trojanizing legitimate Barracuda Lua modules and installing PCAP filters","Lateral movement executed through SMTP traffic from compromised appliances","Exfiltrates data via web services or alternative protocols","Executes reverse shells and downloads secondary payloads with wget","Implements ransomware (Royal Ransomware) for extortion"], mitre_techniques":["T1190","T1203","T1566.001","T1041","T1071.003","T1105","T1497","T1133","T1497.001","T1497.002","T1497.003","T1567","T1048","T1486"], mitre_tactics":["Initial Access","Execution","Persistence","Defense Evasion","Lateral Movement","Exfiltration","Command and Control"], associated_tools":["SALTWATER","SEASPY","SEASIDE","CSmtp","SEASPRAY","SKIPJACK","cd00r","Royal Ransomware"], campaign_insights":"Barracuda’s campaign leveraged the CVE-2023‑2868 zero‑day in Barracuda ESG appliances, delivering malicious TAR files via phishing emails. The group spread from October 2022 to May 2023, affecting multiple countries and sectors. Tactics included remote code execution, backdoor installation, SMTP‑based lateral movement, exfiltration over web services, and subsequent ransomware installation for extortion. The operation’s cadence was rapid, with many victims infected within short time frames.", ioc_patterns":["Specially crafted .tar file attachments using special characters to exploit CVE-2023-2868","Phishing emails with generic subject/body and placeholder values","Spoofed email 'from' addresses using non-existent or unowned domains","Use of CSmtp command-line utility on compromised appliances for outbound mail","TAR archive attachment exploiting CVE-2023-2868 with malicious filename containing single quote or backtick","Wget commands used to download secondary payloads from attacker servers","Backdoor files embedded in TAR archives that include shell scripts for persistence"], recommended_actions":["Apply Barracuda ESG patches released in May 2023 that address CVE‑2023‑2868","Disable unnecessary external email functions and harden appliance authentication configurations","Monitor for anomalous emails with TAR attachments or mismatched file extensions","Perform regular vulnerability scanning of Barracuda appliances to detect unpatched flaws","Enable comprehensive logging on SMTP services to detect lateral movement patterns via CSmtp commands","Implement email filtering rules to block suspicious TAR attachments containing special characters","Monitor outbound traffic on SMTP ports (25/587) for unusual connection attempts or command execution signatures","Conduct integrity checks of Lua modules and PCAP filters on Barracuda appliances to detect trojanization"], suggested_tags":["UNC4841","APT44","China-nexus actor","Espionage","CVE-2023-2868","Barracuda ESG","SALTWATER","SEASPY","SEASIDE","CSmtp","Phishing Email Attachments","Remote Command Injection","Backdoor: SEASPY","Backdoor: SALTWATER","Trojanized Module","China Espionage","Royal Ransomware"], confidence_assessment":"The evidence for Barracuda’s exploitation of CVE‑2023‑2868, use of phishing with malicious TAR attachments, and installation of backdoors such as SALTWATER/SEASPY/SEASIDE is high confidence due to multiple independent reports. Confidence in the ransomware component (Royal Ransomware) remains moderate because only limited references exist; further corroboration would strengthen this claim. Overall data gaps include detailed attribution evidence, extent of operations post‑May 2023, and precise financial impact metrics.", sources":["https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/barracuda-email-security-gateway-esg-malicious-activity-additional-indicators-compromise-released","https://www.cisa.gov/news-events/alerts/2023/06/15/barracuda-networks-releases-update-address-esg-vulnerability*_sp=4b218e08-d46e-4a47-86a5-8886400560ec","https://blog.barracuda.com/2024/02/12/royal-ransomware--a-threat-actor-you-should-know"]}

Enhanced Description

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 2 SHA-1 Hash 2 SHA-256 Hash 2 Domain 6 MD5 Hash 7 Email Address 1

References

  1. cloud.google.com — Cited by web research for: sectors
  2. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  3. attack.mitre.org — Cited by web research for: T1497.001

Intel Summary

10

Techniques

40

Tools

4

Campaigns

40

IOCs

0

Observed Data

5

Tactics

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Country of Origin
China (CN)
Confidence
80%
First Seen
Aug 5, 2026
Last Seen
Aug 6, 2026
Added
Aug 6, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.