SEASPRAY is a Lua-based backdoor and launcher implanted into legitimate Barracuda Email Security Gateway modules during compromises associated with exploitation of CVE-2023-2868. It is associated with UNC4841 and was used in post-compromise operations on Barracuda ESG appliances to maintain access and trigger follow-on payloads. The malware is implemented as a trojanized email-processing module that registers event handlers for incoming email activity, particularly attachments, and in some variants also evaluates sender-related conditions. When predefined trigger values are present in processed email traffic, SEASPRAY invokes operating-system command execution to launch an external payload, most notably WHIRLPOOL, which provides reverse-shell access.
SEASPRAY is notable for blending into the appliance’s normal mail-handling workflow rather than operating as a standalone userland implant. By embedding malicious logic inside legitimate Lua modules used by the Barracuda SMTP and email-processing stack, it gains persistence and execution opportunities tied to routine message handling. Reported variants monitor incoming attachments, copy selected content for execution flow, or trigger on special markers in sender or attachment metadata. Its primary operational role is as a lightweight launcher and backdoor component that enables command-and-control activation of additional malware while remaining tailored to the Barracuda ESG environment.
The malware has been observed in campaigns targeting Barracuda Email Security Gateway appliances across multiple sectors and countries, consistent with espionage-oriented activity. In the broader intrusion set, SEASPRAY was deployed alongside other Barracuda-focused malware families including WHIRLPOOL, SEASPY, SALTWATER, SKIPJACK, and SUBMARINE. Its use reflects a platform-specific approach in which threat actors exploited edge appliances with limited defensive visibility and then installed custom persistence and access tooling adapted to those systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The device was compromised by threat actors exploiting CVE-2023-2868, a former zero-day vulnerability affecting versions 5.1.3.001-9.2.0.006 of Barracuda Email Security Gateway (ESG). | This artifact is a trojanized Lua module that has been identified as a "SEASPRAY" variant. SEASPRAY registers an event handler for all incoming email attachments.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SEASPRAY is a launcher written in Lua that UNC4841 injected into legitimate Barracuda Email Security Gateway (ESG) modules.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
Mandiant has observed a trend in which China-nexus attackers have gained access to edge devices via exploitation of vulnerabilities, particularly zero-days... If an attacker possesses an exploit for a zero-day vulnerability on these devices, they are often able to gain access to a target environment and remain undetected for an extended period of time.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Post-exploitation malware deployed after Barracuda ESG compromise to maintain persistence in victim environments.
A Lua-based launcher injected into legitimate Barracuda ESG modules; it registers an event handler for incoming emails and launches WHIRLPOOL when specific markers are present.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.