SALTWATER is a Linux backdoor associated with exploitation of Barracuda Email Security Gateway appliances, particularly through CVE-2023-2868, and later reported in follow-on Barracuda exploitation activity. It is implemented as a trojanized module for the Barracuda SMTP daemon and has been attributed to the China-nexus espionage cluster UNC4841. The malware was used post-compromise to establish durable access on affected email security appliances and to support espionage-oriented operations.
SALTWATER operates as a shared-object implant on Barracuda ESG systems and provides command execution, file upload and download, proxying, and traffic tunneling. Technical analysis shows it hooks network-related functions in the SMTP daemon, intercepts socket activity, and spawns worker threads to communicate with attacker-controlled infrastructure over encrypted TLS channels. It can perform DNS resolution, receive structured commands from command and control, execute shell commands with the privileges of the calling process, transfer files in both directions, and relay traffic through proxy and tunnel functionality. Reported channelized capabilities include shell execution, download, upload, proxy, and tunnel configuration.
The malware has been observed alongside other UNC4841 tooling including SEASPY, SEASIDE, SEASPRAY, WHIRLPOOL, SKIPJACK, SUBMARINE, and SANDBAR in Barracuda ESG intrusions. In this intrusion set, SALTWATER formed part of a broader persistence and access framework deployed after successful exploitation of Barracuda appliance vulnerabilities delivered via crafted email attachments. Targeting has included government and private-sector organizations across multiple countries, with activity consistent with long-term intelligence collection and access maintenance on perimeter email infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The device was compromised by threat actors exploiting CVE-2023-2868, a former zero-day vulnerability affecting versions 5.1.3.001-9.2.0.006 of Barracuda Email Security Gateway (ESG). | This artifact, belonging to the SALTWATER malware family, is a 32-bit Linux Shared Object (.so) file.
Barracuda confirme l’observation des deux logiciels malveillants, SEASPY et SALTWATER, exploitant la faille critique « CVE-2023-7102 » au cours des attaques récentes, pour se faire passer pour des modules et des services Barracuda ESG légitimes. | En outre, « SALTWATER » est un module contenant des logiciels malveillants pour le démon SMTP (Simple Mail Transfer Protocol) de Barracuda (bsmtpd) qui prend en charge de nombreuses fonctionnalités telles que le téléchargement de fichiers arbitraires, l'exécution de commandes, ainsi que le proxy et le tunnelage du trafic malveillant afin d'éviter la détection.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"UNC4841 then deployed custom malware, including SALTWATER (a trojanized Simple Mail Transfer Protocol [SMTP] module enabling command execution and tunneling)..."
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware can execute any shell command with the same privileges as its calling process.
Figures 6, 7, and 8 show the malware's capacity to connect to a remote address, and then create a new process with the command line argument '/bin/sh.'
The malware can intake data over the network, using a previously established socket, with the 'recv' function... using 'popen', the malware can execute any shell command with the same privileges as its calling process.
SEASPY est un backdoor persistant x64 qui se fait passer pour un service légitime de Barracuda Networks ... En outre, « SALTWATER » est un module contenant des logiciels malveillants pour le démon SMTP ...
Figure 12 shows the malware creating a new thread, within the calling process. This is thread injection and it can inject two different functions.
Figures 14 and 15 show the second function. The second function can establish communications, over the network, using a TLS version 1 connection.
“SALTWATER (a trojanized SMTP module enabling command execution and tunneling)… SEASIDE… turns SMTP HELO/EHLO data into reverse shells”
Figure 10 shows the malware's capacity to perform DNS resolution, using the system call 'sys_getpeername.' ... Figure 13 shows the first function that can perform DNS resolution.
These backdoors functioned by capturing the SMTP traffic, proxying into victim environments and maintaining persistence.
From the observation, three principle backdoors has been used to be deployed using this vulnerability namely SALTWATER, SEASIDE and SEASPY.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Trojanized SMTP module used on compromised Barracuda ESG appliances to enable command execution and tunneling (persistence/access and likely exfiltration support).
Custom implant described as a trojanized SMTP module on Barracuda ESG that enables command execution and tunneling, supporting persistence and data exfiltration from compromised email security gateways.
Custom implant for Barracuda ESG: a trojanized SMTP module used for command execution and tunneling, turning the email security gateway into a persistent access/exfiltration node.
SALTWATER is a backdoor malware deployed by Chinese APT UNC4841 after exploiting a zero-day in Barracuda Email Security Gateway appliances, used to maintain persistent access and facilitate espionage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.