Also known as: UNC4841, tracked as, the Seapike, APT44, sectors, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, whitelist, Royal Ransomware
Barracuda—also known as UNC4841 or APT44—has been active since mid‑2022 targeting a wide spectrum of sectors including government, finance, healthcare, and critical infrastructure. The group’s primary motivation is financial gain, achieved through ransomware, data theft, and extortion campaigns. Their operations are characterized by sophisticated social engineering via phishing emails that deliver specially crafted TAR files, which exploit the CVE-2023‑2868 vulnerability in Barracuda ESG appliances to achieve remote code execution. Once compromised, attackers use the appliance’s SMTP functionality to move laterally across an organization by sending further malicious payloads from the infected device. They install multiple backdoor modules—SALTWATER, SEASPY, and SEASIDE—which integrate as Trojanized Lua modules or PCAP filters to maintain persistence and provide covert exfiltration channels through web services and alternative protocols. The actors occasionally deploy ransomware, most notably Royal Ransomware, to extort victims after securing data for sale or leverage. The group's geographic focus is broad, with documented attacks in China, the United Kingdom, Taiwan, India, Ukraine, Russia, the US, Germany, Korea, Iran, Azerbaijan, Pakistan, Belarus, Poland, Canada, and Australia. Despite being labeled a “criminal” threat actor, Barracuda’s methods reflect a sophisticated state‑sponsored or at least well‑equipped operation with capabilities mirroring those seen in China‑linked espionage campaigns.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Barracuda is a medium‑sophistication cybercriminal group that leveraged the CVE-2023-2868 remote command injection flaw in Barracuda Email Security Gateway appliances using malicious TAR attachments from October 2022 to May 2023. The actors deployed a suite of backdoors (SALTWATER, SEASPY, SEASIDE) for persistence and data exfiltration, later injecting ransomware such as Royal Ransomware to extort victims.
Goals & Targeting
Barracuda seeks to compromise high‑value infrastructure across diverse industries, primarily to exfiltrate data for monetary gain and later to ransom victims. Their multi‑stage approach—initial exploitation of a critical vendor vulnerability, followed by backdoor persistence, lateral movement via SMTP, covert exfiltration, and optional ransomware payloads—suggests an agenda that combines both commercial espionage and financial extortion. The broad victim set points toward opportunistic targeting rather than narrowly focused political objectives. key_capabilities":["Exploits CVE-2023-2868 via malicious TAR attachments","Uses phishing emails with disguised or spoofed attachments to deliver payloads","Deploys specialized backdoor families such as SALTWATER, SEASPY, and SEASIDE","Permanently persists by trojanizing legitimate Barracuda Lua modules and installing PCAP filters","Lateral movement executed through SMTP traffic from compromised appliances","Exfiltrates data via web services or alternative protocols","Executes reverse shells and downloads secondary payloads with wget","Implements ransomware (Royal Ransomware) for extortion"], mitre_techniques":["T1190","T1203","T1566.001","T1041","T1071.003","T1105","T1497","T1133","T1497.001","T1497.002","T1497.003","T1567","T1048","T1486"], mitre_tactics":["Initial Access","Execution","Persistence","Defense Evasion","Lateral Movement","Exfiltration","Command and Control"], associated_tools":["SALTWATER","SEASPY","SEASIDE","CSmtp","SEASPRAY","SKIPJACK","cd00r","Royal Ransomware"], campaign_insights":"Barracuda’s campaign leveraged the CVE-2023‑2868 zero‑day in Barracuda ESG appliances, delivering malicious TAR files via phishing emails. The group spread from October 2022 to May 2023, affecting multiple countries and sectors. Tactics included remote code execution, backdoor installation, SMTP‑based lateral movement, exfiltration over web services, and subsequent ransomware installation for extortion. The operation’s cadence was rapid, with many victims infected within short time frames.", ioc_patterns":["Specially crafted .tar file attachments using special characters to exploit CVE-2023-2868","Phishing emails with generic subject/body and placeholder values","Spoofed email 'from' addresses using non-existent or unowned domains","Use of CSmtp command-line utility on compromised appliances for outbound mail","TAR archive attachment exploiting CVE-2023-2868 with malicious filename containing single quote or backtick","Wget commands used to download secondary payloads from attacker servers","Backdoor files embedded in TAR archives that include shell scripts for persistence"], recommended_actions":["Apply Barracuda ESG patches released in May 2023 that address CVE‑2023‑2868","Disable unnecessary external email functions and harden appliance authentication configurations","Monitor for anomalous emails with TAR attachments or mismatched file extensions","Perform regular vulnerability scanning of Barracuda appliances to detect unpatched flaws","Enable comprehensive logging on SMTP services to detect lateral movement patterns via CSmtp commands","Implement email filtering rules to block suspicious TAR attachments containing special characters","Monitor outbound traffic on SMTP ports (25/587) for unusual connection attempts or command execution signatures","Conduct integrity checks of Lua modules and PCAP filters on Barracuda appliances to detect trojanization"], suggested_tags":["UNC4841","APT44","China-nexus actor","Espionage","CVE-2023-2868","Barracuda ESG","SALTWATER","SEASPY","SEASIDE","CSmtp","Phishing Email Attachments","Remote Command Injection","Backdoor: SEASPY","Backdoor: SALTWATER","Trojanized Module","China Espionage","Royal Ransomware"], confidence_assessment":"The evidence for Barracuda’s exploitation of CVE‑2023‑2868, use of phishing with malicious TAR attachments, and installation of backdoors such as SALTWATER/SEASPY/SEASIDE is high confidence due to multiple independent reports. Confidence in the ransomware component (Royal Ransomware) remains moderate because only limited references exist; further corroboration would strengthen this claim. Overall data gaps include detailed attribution evidence, extent of operations post‑May 2023, and precise financial impact metrics.", sources":["https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/barracuda-email-security-gateway-esg-malicious-activity-additional-indicators-compromise-released","https://www.cisa.gov/news-events/alerts/2023/06/15/barracuda-networks-releases-update-address-esg-vulnerability*_sp=4b218e08-d46e-4a47-86a5-8886400560ec","https://blog.barracuda.com/2024/02/12/royal-ransomware--a-threat-actor-you-should-know"]}
Enhanced Description
No observed data linked yet.
10
Techniques
40
Tools
4
Campaigns
40
IOCs
0
Observed Data
5
Tactics