Barracuda Zero-Day Exploited by Chinese Actor

According to Mandiant, a zero-day vulnerability in Barracuda Email Security Gateway (ESG) discovered in late May has been exploited for Chinese espionage beginning in October 2022.

A new report from the Google-owned threat intelligence firm revealed yesterday that a new threat actor, UNC4841, began sending phishing emails on October 10th of last year.

These malicious emails contained attachments intended to exploit Barracuda bug CVE-2023-2868 to gain initial access to vulnerable appliances, it added.

Read more about China’s APT activity: Cyber ​​warfare escalates amid China-Taiwan tensions.

Once a foothold was established, the group used Saltwater, Seaside, and Seaspray malware to masquerade as legitimate Barracuda ESG modules or services to maintain their presence on the device.

“Following the initial breach, Mandiant and Barracuda actively targeted specific data of interest to UNC4841 for exploitation and, in some cases, used access to ESG appliances to perform lateral movement into victim networks. and have observed it sending emails to other victim appliances.”

“Mandiant also observed that UNC4841 has deployed additional tools to maintain its presence on ESG appliances.”

Barracuda discovered this campaign on May 19th and two days later released a patch to contain and remediate the threat. However, the threat group switched malware and introduced new persistence mechanisms to maintain access, Mandiant explained.

From May 22nd to May 24th, UNC4841 targeted victims in 16 countries in a “high frequency” operation, and Barracuda took the unusual step of urging customers to quarantine and replace their appliances regardless of their patch status. took action.

The security vendor was recognized for its responsiveness and sharing of product-specific expertise that enabled a full-fledged investigation.

However, the UNC4841 threat still exists.

“UNC4841 has been shown to be highly sensitive to defensive efforts and aggressively modifies TTPs to maintain operations. and we strongly recommend investigating the affected network,” concluded Mandiant.

“We expect UNC4841 to continue to modify TTPs and change toolkits, especially as network defenders continue to take action against this actor and their activities are further exposed by the information security community.”

The actor is believed to be an espionage agent working to aid the Chinese government. A third of the victims were government agencies, but specific targets included prominent academics from Taiwan and Hong Kong, as well as high-ranking government officials from Asia in Southeast Asia and Europe.

Editorial image credit: Ken Wolter / Shutterstock.com

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *