WHIRLPOOL is a Linux backdoor used in the Barracuda Email Security Gateway intrusion set associated with exploitation of CVE-2023-2868 and activity attributed to UNC4841. It is a simple C-based utility delivered as a 64-bit ELF executable that establishes a TLS-protected reverse shell to attacker-controlled infrastructure, enabling remote command execution on compromised appliances. WHIRLPOOL has been observed launched by trojanized Barracuda Lua modules including SEASPRAY and used alongside related malware such as SEASIDE, SKIPJACK, SALTWATER, SEASPY, and SUBMARINE as part of a broader post-compromise ecosystem on Barracuda ESG devices.
Operationally, WHIRLPOOL accepts runtime connection parameters and can connect to a remote address, spawn a shell, and create a new process for interactive control. Analysis has shown environment and host-awareness behavior including checks of processor vendor and architecture, kernel version discovery, interaction with local name-service facilities, and access to common system and account information files during execution. Its role in observed campaigns was primarily post-exploitation remote access rather than autonomous propagation or credential theft.
WHIRLPOOL has been tied to espionage-oriented operations targeting Barracuda ESG appliances, a class of edge devices that often have limited defensive visibility. In observed intrusions, initial access was obtained through exploitation of the Barracuda ESG email attachment screening vulnerability CVE-2023-2868, after which trojanized modules and backdoors were implanted for persistence, command and control, and follow-on operations. The malware’s simplicity and appliance-specific deployment make it notable as a purpose-built reverse-shell component within a tailored edge-device malware ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The device was compromised by threat actors exploiting CVE-2023-2868, a former zero-day vulnerability affecting versions 5.1.3.001-9.2.0.006 of Barracuda Email Security Gateway (ESG). | This artifact, belonging to the WHIRLPOOL malware family, is a 64-bit Linux Executable and Linkable Format (ELF) file.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WHIRLPOOL is a simple TLS reverse shell utility that receives a C2 IP address and port to connect to from SEASPRAY at runtime.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
Mandiant has observed a trend in which China-nexus attackers have gained access to edge devices via exploitation of vulnerabilities, particularly zero-days... If an attacker possesses an exploit for a zero-day vulnerability on these devices, they are often able to gain access to a target environment and remain undetected for an extended period of time.
The malware can execute any shell command with the same privileges as its calling process.
The malware further access the following files at runtime: ... /etc/passwd ... /etc/group ... /etc/gshadow /etc/shadow ...
The malware accesses the target's environment variables. See below list below: --Begin Accessed Environment Variables-- GCONV_PATH GETCONF_DIR HTTPS_PROXY HTTP_PROXY LANG LANGUAGE LC_ALL ... | The malware checks processor hardware and architecture, to include if the target system uses AMD or Intel... Figure 5 shows the malware determining the kernel version by invoking the 'uname' command line function and exploring the contents of the '/proc/sys/kernel/osrelease' file.
Figures 14 and 15 show the second function. The second function can establish communications, over the network, using a TLS version 1 connection.
“SEASIDE…monitors SMTP HELO/EHLO commands to receive an encoded C2 IP address and port…”
Figure 10 shows the malware's capacity to perform DNS resolution, using the system call 'sys_getpeername.' ... Figure 13 shows the first function that can perform DNS resolution.
SEASPRAY registers an event handler for incoming emails, and launches an external binary, which Mandiant tracks as WHIRLPOOL, when certain markers are present.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Whirlpool is a malware variant used to gain unauthorized access to Barracuda ESG appliances by exploiting a critical vulnerability, enabling attackers to maintain persistence and control over compromised devices.
A simple TLS reverse shell launched by SEASPRAY that receives runtime C2 connection parameters.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.