SEASPY is a persistent, passive Linux backdoor used in espionage activity targeting Barracuda Email Security Gateway appliances. It is closely associated with exploitation of CVE-2023-2868, a remote command injection vulnerability in Barracuda ESG, and has also been reported in follow-on Barracuda exploitation activity. The malware masquerades as a legitimate Barracuda service, commonly using the service name BarracudaMailService, to blend into the appliance environment and maintain covert access.
SEASPY operates by passively monitoring network traffic with libpcap and waiting for specially crafted trigger traffic on SMTP-related ports. When the expected packet sequence and embedded trigger value are observed, it initiates a reverse shell to attacker-controlled infrastructure, enabling arbitrary command execution on the compromised appliance. This design reduces its network exposure until activated and makes it analogous to other so-called magic-packet backdoors. Reported samples were 64-bit ELF binaries for GNU/Linux, and analysis has assessed the malware as derived from the open-source backdoor cd00r.
The malware was deployed by the China-nexus espionage cluster tracked as UNC4841 following compromise of Barracuda ESG devices. It formed part of a broader post-exploitation toolkit that also included SALTWATER, SEASIDE, WHIRLPOOL, SEASPRAY, SKIPJACK, SUBMARINE, and SANDBAR. UNC4841 used SEASPY to maintain long-term access to victim environments, including persistence across reboots through startup modifications and related persistence mechanisms on the appliance. In some intrusions, additional tooling was used to conceal or support SEASPY, including rootkit functionality intended to hide processes associated with its masqueraded service name.
Victimology linked to the broader Barracuda campaign spans government and private-sector organizations worldwide, with significant espionage interest in email data and access to downstream networks. SEASPY’s role in that activity was to provide covert remote access on compromised ESG appliances, supporting sustained post-exploitation operations and follow-on intrusion activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CISA has published three malware analysis reports on malware variants associated with exploitation of CVE-2023-2868. CVE-2023-2868 is a remote command injection vulnerability affecting Barracuda Email Security Gateway (ESG) Appliance, versions 5.1.3.001-9.2.0.006. It was exploited as a zero day as early as October 2022 to gain access to ESG appliances. | SEASPY – SEASPY is a persistent and passive backdoor that masquerades as a legitimate Barracuda service.
Barracuda confirme l’observation des deux logiciels malveillants, SEASPY et SALTWATER, exploitant la faille critique « CVE-2023-7102 » au cours des attaques récentes, pour se faire passer pour des modules et des services Barracuda ESG légitimes. | Barracuda confirme l’observation des deux logiciels malveillants, SEASPY et SALTWATER, exploitant la faille critique « CVE-2023-7102 » au cours des attaques récentes, pour se faire passer pour des modules et des services Barracuda ESG légitimes. Il est à noter que « SEASPY » est un backdoor persistant x64 qui se fait passer pour un service légitime de Barracuda Networks et se fait passer pour un filtre PCAP, surveillant spécifiquement le trafic sur le port 25.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...SEASPY (a backdoor masquerading as BarracudaMailService triggered by “magic packets”)..."
23 distinct techniques documented for this family, organized by ATT&CK tactic.
“execution of their initial reverse shell via hourly and daily cron jobs… /etc/cron.hourly/… /etc/cron.daily/…”
This allows the TA to execute arbitrary commands on the compromised system. | When the right sequence of packet is captured, it establishes a TCP reverse shell to the TA's C2 server for further exploitation.
“persistently executed SEASPY on appliance reboot through…addition to /etc/init.d/rc…”
“execution of their initial reverse shell via hourly and daily cron jobs… /etc/cron.hourly/… /etc/cron.daily/…”
SEASPY prend également en charge une fonctionnalité de backdoor activé par un "magic packet"
SEASPY is a persistent and passive backdoor that masquerades as a legitimate Barracuda service.
“persistently executed SEASPY on appliance reboot through…addition to /etc/init.d/rc…”
“execution of their initial reverse shell via hourly and daily cron jobs… /etc/cron.hourly/… /etc/cron.daily/…”
SEASPY is a persistent and passive backdoor that masquerades as a legitimate Barracuda service “BarracudaMailService”
“UNC4841 has repeatedly utilized time-stomping to further hide their malicious activity.”
SALTWATER is a backdoor that can perform DNS resolution and establish communications, over the network, using a TLS version 1 connection.
“SALTWATER (a trojanized SMTP module enabling command execution and tunneling)… SEASIDE… turns SMTP HELO/EHLO data into reverse shells”
These backdoors functioned by capturing the SMTP traffic, proxying into victim environments and maintaining persistence.
The reverse shell establishes communication with the threat actor’s command and control (C2) server, from where it downloads the SEASPY backdoor to the ESG appliance.
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor described as magic-packet malware targeting Barracuda Networks Email Security Gateway appliances.
Backdoor implant on Barracuda ESG appliances that masquerades as a legitimate service and is activated via specially crafted network traffic (“magic packets”).
Custom backdoor used on Barracuda ESG; masquerades as a legitimate service and is triggered via specially crafted network traffic (“magic packets”) to provide covert access.
Custom backdoor used on Barracuda ESG appliances; masquerades as a legitimate service and is activated via specially crafted network traffic (“magic packets”) to maintain covert persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.