Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 1 actorExploits 2 CVEs

SEASIDE

SEASIDE is a Lua-based malicious module targeting Barracuda Networks Email Security Gateway (ESG) appliances by integrating with the Barracuda SMTP daemon (bsmtpd). It monitors SMTP HELO/EHLO commands to receive an encoded command-and-control (C2) IP address and port, decodes the C2 parameters, and passes them as arguments to an external binary, WHIRLPOOL, which then establishes a reverse shell (including TLS reverse shell capability as described for WHIRLPOOL). SEASIDE was deployed by the China-nexus espionage actor UNC4841 following exploitation of Barracuda ESG zero-day vulnerabilities (notably CVE-2023-2868, a remote command injection in the attachment-scanning component triggered via crafted .tar archives and Perl’s qx operator). Reporting indicates UNC4841 used SEASIDE alongside other custom payloads (SALTWATER and SEASPY) to establish and maintain long-term access on Barracuda ESG appliances, with observed dwell time up to approximately eight months. UNC4841 has been observed time-stomping when deploying SEASIDE to hinder detection and timeline analysis. No specific host/network indicators (hashes, domains, IPs) for SEASIDE are provided in the content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

2 CVES
CVE-2023-2868Remote Command Injection in Barracuda Email Security Gateway ApplianceExploited in the wild

...UNC4841 exploited Barracuda ESG zero-day vulnerabilities... malicious email attachments to trigger remote command injection in the ESG attachment-scanning component (CVE-2023-2868)... Crafted .tar archives abused Perl’s qx operator to execute arbitrary system commands...

via recorded future blogrecordedfuture.com
CVE-2023-7102Parameter Injection in Barracuda ESG via Spreadsheet::ParseExcel

"...and SEASIDE (a Lua module that turns SMTP HELO/EHLO data into reverse shells)..."

via recorded future blogrecordedfuture.com
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UNC4841

"...and SEASIDE (a Lua module that turns SMTP HELO/EHLO data into reverse shells)..."

via recorded future blogrecordedfuture.com
MITRE ATT&CK

Techniques & procedures

7 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1190Exploit Public-Facing ApplicationEvidence1

“Crafted .tar archives abused Perl’s qx operator to execute arbitrary system commands on the gateway… (CVE-2023-2868)”

T1566.001Spearphishing AttachmentEvidence1

“used malicious email attachments to trigger remote command injection… Crafted .tar archives… execute arbitrary system commands… follow-on… malicious Excel attachments”

Execution

2 techniques
T1059Command and Scripting InterpreterEvidence1

“remote command injection… Crafted .tar archives abused Perl’s qx operator to execute arbitrary system commands on the gateway”

T1059.004Unix ShellEvidence1

“WHIRLPOOL…establishes a reverse shell.” / “WHIRLPOOL is a C based utility used to create a TLS reverse shell.”

Stealth

1 technique
T1070.006TimestompEvidence1

“UNC4841 has repeatedly utilized time-stomping to further hide their malicious activity.”

Command and Control

2 techniques
T1071.003Mail ProtocolsEvidence2

“SALTWATER (a trojanized SMTP module enabling command execution and tunneling)… SEASIDE… turns SMTP HELO/EHLO data into reverse shells”

T1090ProxyEvidence1

“SALTWATER… enabling command execution and tunneling)… SEASPY… backdoor… SEASIDE… turns SMTP HELO/EHLO data into reverse shells…”

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities2

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping7

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.