UNC4841 is a China-linked cyber espionage threat actor assessed to operate in support of the People’s Republic of China. The group is best known for long-running exploitation of Barracuda Email Security Gateway appliances, including the zero-day CVE-2023-2868, to obtain covert access to victim networks across multiple regions and sectors. Reporting also notes infrastructure overlap and tradecraft similarities with other PRC-linked activity clusters, including Salt Typhoon, though this overlap has been assessed as consistent with shared infrastructure procurement or support rather than proof that the same operators are identical. UNC4841 specializes in compromising edge devices and other security appliances that often have limited endpoint visibility and weak forensic coverage. In Barracuda ESG intrusions, the actor deployed a tailored malware ecosystem including SALTWATER, SEASPY, SEASIDE, SEASPRAY, SKIPJACK, WHIRLPOOL, DEPTHCHARGE, and the SANDBAR rootkit. These tools provided reverse shell access, command execution, file transfer, proxying and tunneling, passive backdoor functionality, and stealth features designed for the Barracuda platform. The actor repeatedly modified malware components during remediation efforts, used time-stomping to conceal deployment, trojanized legitimate Lua modules, abused startup scripts and cron-based persistence, and in some cases used a kernel rootkit to hide malicious processes. A notable UNC4841 persistence technique involved DEPTHCHARGE, which embedded persistence into the Barracuda ESG configuration database so that compromised backup exports could reinfect replacement appliances when restored. The actor also abused database triggers and application logic to regain execution during configuration import. This demonstrated a strong focus on durable access and resistance to incident response measures. UNC4841 has conducted targeted collection and exfiltration from compromised email security appliances, including staging and exporting email-related data and searching mail stores for communications associated with selected users or domains. Victimology spans public- and private-sector organizations worldwide, with observed targeting including government entities and officials, as well as academics in Taiwan and Hong Kong and government-linked targets in Southeast Asia and Europe. One-third of known Barracuda ESG victims were reported to be government agencies across at least 16 countries. Limited post-compromise reconnaissance has also been observed, including subnet and service discovery using open-source tooling. The actor’s tradecraft is consistent with strategic intelligence collection rather than financially motivated crime. UNC4841 is part of a broader pattern of PRC-linked operators investing in zero-day exploitation and platform-specific malware for edge infrastructure in order to evade detection, maintain persistence, and support long-term espionage operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
24 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
...UNC4841 exploited Barracuda ESG zero-day vulnerabilities... malicious email attachments to trigger remote command injection in the ESG attachment-scanning component (CVE-2023-2868)... Crafted .tar archives abused Perl’s qx operator to execute arbitrary system commands...
Barracuda later disclosed follow-on exploitation of CVE-2023-7102 in the Spreadsheet::ParseExcel library, again via malicious Excel attachments, to reinstall updated SEASPY and SALTWATER variants after initial remediation.
32 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-nexus espionage activity exploiting Barracuda Email Security Gateway (ESG) vulnerabilities (notably CVE-2023-2868 and later CVE-2023-7102) via malicious attachments to gain code execution on ESG appliances, then deploying bespoke implants (SALTWATER, SEASPY, SEASIDE) for persistence, command execution, tunneling, and exfiltration; linked to compromise of Belgium’s VSSE email flows.
China-nexus espionage activity exploiting Barracuda Email Security Gateway vulnerabilities (notably CVE-2023-2868 and later CVE-2023-7102) via malicious attachments to gain code execution on ESG appliances, then deploying bespoke implants (SALTWATER, SEASPY, SEASIDE) for persistence, command execution, tunneling, and exfiltration; linked to compromise of Belgium’s VSSE email flows.
China-nexus espionage activity exploiting Barracuda Email Security Gateway (ESG) vulnerabilities (including CVE-2023-2868 and later CVE-2023-7102) via malicious attachments to gain and maintain persistent access to email gateway infrastructure, enabling long-term collection/exfiltration (including reported compromise of Belgium’s VSSE email flows).
China-linked cluster associated with infrastructure (domains) tied to Salt Typhoon activity; details not expanded in provided content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.