Hackers Deploy SUBMARINE Backdoor in Barracuda Email Security Gateway Attacks

Teilen:

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday disclosed details of a novel persistent backdoor called SUBMARINE deployed by threat actors in connection with the hack on Barracuda Email Security Gateway (ESG) appliances.

SUBMARINE comprises multiple artifacts — including a SQL trigger, shell scripts, and a loaded library for a Linux daemon — that together enable execution with root privileges, persistence, command and control, and cleanup, the agency said.

The findings come from an analysis of malware samples obtained from an unnamed organization that had been compromised by threat actors exploiting a critical flaw in ESG devices, CVE-2023-2868 (CVSS score: 9.8), which allows for remote command injection.

Evidence gathered so far shows that the attackers behind the activity, a suspected China nexus-actor tracked by Mandiant as UNC4841, leveraged the flaw as a zero-day in October 2022 to gain initial access to victim environments and implanted backdoors to establish and maintain persistence.

To that end, the infection chain involved sending phishing emails with booby-trapped TAR file attachments to trigger exploitation, leading to the deployment of a reverse shell payload to establish communication with the threat actor’s command-and-control (C2) server, from where a passive backdoor known as SEASPY is downloaded for executing arbitrary commands on the device.

SUBMARINE, also codenamed DEPTHCHARGE by the Google-owned threat intelligence firm, is the latest malware family to be discovered in connection with the operation. Executed with root privileges, it resides in a Structured Query Language (SQL) database on the ESG appliance, and receives encrypted commands and hides its responses in SMTP traffic.

It’s believed to have been deployed in response to remediation efforts, echoing Mandiant’s characterization of the adversary as an aggressive actor capable of quickly altering their malware and employing additional persistence mechanisms in an attempt to maintain their access.

The agency further said it analyzed artifacts related to SUBMARINE that contained the contents of the compromised SQL database, and that it poses a severe threat for lateral movement.

Update#

Barracuda, in a revised advisory, said SUBMARINE appeared on a very small number of already compromised ESG appliances, emphasizing that customers should discontinue use of the compromised ESG appliance and contact Barracuda support to obtain a new ESG virtual or hardware appliance.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
10:27 am, Juli 13, 2025
Wetter-Symbol 22°C
L: 20° | H: 23°
klarer Himmel
Luftfeuchtigkeit: 66 %
Druck: 1013 mb
Wind: 4 mph NE
Windböe: 5 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 2%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:58 am
Sonnenuntergang: 9:13 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
20° | 23°°C 0 mm 0% 6 mph 57 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
19° | 27°°C 0 mm 0% 15 mph 71 % 1015 mb 0 mm/h
Di. Juli 15 10:00 pm
Wetter-Symbol
15° | 22°°C 1 mm 100% 17 mph 85 % 1016 mb 0 mm/h
Mi. Juli 16 10:00 pm
Wetter-Symbol
14° | 27°°C 0.11 mm 11% 11 mph 85 % 1017 mb 0 mm/h
Do. Juli 17 10:00 pm
Wetter-Symbol
18° | 27°°C 1 mm 100% 13 mph 95 % 1015 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
24° | 27°°C 0 mm 0% 3 mph 57 % 1013 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
27° | 30°°C 0 mm 0% 0 mph 39 % 1011 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 6 mph 31 % 1008 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 6 mph 40 % 1010 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 5 mph 40 % 1011 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 5 mph 52 % 1010 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 9 mph 71 % 1011 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
23° | 23°°C 0 mm 0% 12 mph 54 % 1012 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,851.47
-0.12%
Ethereum(ETH)
€2,524.95
-0.62%
XRP(XRP)
€2.38
-0.88%
Fesseln(USDT)
€0.86
-0.01%
Solana(SOL)
€138.69
-0.27%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.169484
-1.33%
Shiba Inu(SHIB)
€0.000011
-1.70%
Pepe(PEPE)
€0.000010
-2.19%
Peanut das Eichhörnchen(PNUT)
€0.246209
7.19%
Nach oben scrollen