Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
8 malware familiesExploits CVEs in the wild

UNC4841

Also known asUNC4841

UNC4841 is a China-linked, suspected Chinese cyber-espionage threat actor assessed by Mandiant as operating in support of the People’s Republic of China (PRC). The group is associated with long-term espionage activity across multiple regions and sectors, and is known for favoring internet-facing edge devices as an access vector. UNC4841 is best known for exploiting Barracuda Email Security Gateway (ESG) zero-day vulnerability CVE-2023-2868, with exploitation reported as active since at least October 2022, to gain access to networks and conduct long-term espionage. Reporting also notes follow-on exploitation of CVE-2023-7102 in Barracuda ESG appliances. In the Barracuda ESG campaign, UNC4841 deployed custom malware including SALTWATER, SEASPY, and SEASIDE. SALTWATER is a backdoor module for the Barracuda SMTP daemon (bsmtpd) that supports file upload/download, command execution, proxying, and tunneling, and was deployed with time-stomping to hide activity. SEASIDE is a Lua-based bsmtpd module that monitors SMTP HELO/EHLO commands, decodes an encoded C2 address and port, and launches the WHIRLPOOL reverse shell utility. Mandiant also identified trojanized Lua modules associated with SEASPRAY and SKIPJACK, as well as SANDBAR, a Linux rootkit used to hide processes. Persistence mechanisms included cron jobs, init script modification, insertion of execution commands into a Perl update script, and startup-loaded kernel module deployment. UNC4841 staged email-related data into .tar.gz archives under /mail/tmp/ and exfiltrated them over TLS using openssl s_client; in limited cases it used anonfiles. Mandiant also observed limited reconnaissance using the open-source fscan tool. Victimology spans public and private sector organizations worldwide. Reporting states attacks affected multiple regions and sectors, with one-third of Barracuda ESG victims reportedly government agencies from at least 16 countries. Targeted collection included academics in Taiwan and Hong Kong and Asian and European government officials in Southeast Asia. Reporting also links UNC4841 exploitation of Barracuda ESG appliances to espionage activity affecting Belgium’s VSSE. Additional reporting notes infrastructure overlap and similar TTPs with Salt Typhoon, including use of 45 domains registered as early as May 2020 to facilitate cyber-espionage operations. Mandiant assessed observed overlaps likely indicate shared infrastructure procurement support rather than the same operators. The only alias directly provided in the content for this actor is UNC4841.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

9 of 15 tactics34 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1190×2
Exploit Public-Facing Application
T1566
Phishing
T1566.001
Spearphishing Attachment
TA0002
Execution
2 techniques
T1053
Scheduled Task/Job
T1053.003
Cron
T1059
Command and Scripting Interpreter
T1059.004
Unix Shell
TA0003
Persistence
3 techniques
T1037
Boot or Logon Initialization Scripts
T1037.004
RC Scripts
T1053
Scheduled Task/Job
T1053.003
Cron
T1543
Create or Modify System Process
T1543.003
Windows Service
TA0004
Privilege Escalation
3 techniques
T1037
Boot or Logon Initialization Scripts
T1037.004
RC Scripts
T1053
Scheduled Task/Job
T1053.003
Cron
T1543
Create or Modify System Process
T1543.003
Windows Service
TA0005
Stealth
5 techniques
T1014
Rootkit
T1036
Masquerading
T1070
Indicator Removal
T1070.006
Timestomp
T1140
Deobfuscate/Decode Files or Information
T1564
Hide Artifacts
T1564.001
Hidden Files and Directories
TA0007
Discovery
1 technique
T1046
Network Service Discovery
TA0009
Collection
2 techniques
T1114
Email Collection
T1560
Archive Collected Data
TA0011
Command and Control
2 techniques
T1071
Application Layer Protocol
T1071.003×2
Mail Protocols
T1090
Proxy
TA0010
Exfiltration
2 techniques
T1041
Exfiltration Over C2 Channel
T1567
Exfiltration Over Web Service
IOCS

Observables

32 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

recorded future blogNews
Feb 19, 2026
2025 Cloud Threat Hunting and Defense Landscape

China-nexus espionage activity exploiting Barracuda Email Security Gateway (ESG) vulnerabilities (notably CVE-2023-2868 and later CVE-2023-7102) via malicious attachments to gain code execution on ESG appliances, then deploying bespoke implants (SALTWATER, SEASPY, SEASIDE) for persistence, command execution, tunneling, and exfiltration; linked to compromise of Belgium’s VSSE email flows.

Read more
recorded future blogNews
Feb 19, 2026
2025 Cloud Threat Hunting and Defense Landscape

China-nexus espionage activity exploiting Barracuda Email Security Gateway vulnerabilities (notably CVE-2023-2868 and later CVE-2023-7102) via malicious attachments to gain code execution on ESG appliances, then deploying bespoke implants (SALTWATER, SEASPY, SEASIDE) for persistence, command execution, tunneling, and exfiltration; linked to compromise of Belgium’s VSSE email flows.

Read more
recorded future blogNews
Feb 19, 2026
2025 Cloud Threat Hunting and Defense Landscape

China-nexus espionage activity exploiting Barracuda Email Security Gateway (ESG) vulnerabilities (including CVE-2023-2868 and later CVE-2023-7102) via malicious attachments to gain and maintain persistent access to email gateway infrastructure, enabling long-term collection/exfiltration (including reported compromise of Belgium’s VSSE email flows).

Read more
cloudatg insightsNews
Feb 13, 2026
AI Development & Software Engineering | CloudATG

China-linked cluster associated with infrastructure (domains) tied to Salt Typhoon activity; details not expanded in provided content.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping20

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal8

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs2

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables32

Domains, IPs, and hashes tied to this actor, refreshed continuously.