The urgency to replace Barracuda email gateways has heightened as the U.S. Computer and Infrastructure Security Agency (CISA) issued a warning about the discovery of three malware variants on vulnerable devices.
Earlier this year, Barracuda advised users to replace affected email security gateways due to a remote code execution bug (CVE-2023-2868). However, some devices still remain in service, and CISA has now identified three malware variants found on Barracuda devices.
The first malware variant serves as a payload to enable attackers to execute a reverse shell on the ESG appliance. This, in turn, downloads a second backdoor called SEASPY from the command and control (C2) server. SEASPY is disguised as a legitimate Barracuda service, allowing it to monitor traffic from the C2 server. When a specific packet sequence is sent from the server, SEASPY establishes a TCP reverse shell to the C2 server, granting threat actors the ability to execute arbitrary commands on the appliance.
The third malware variant, known as SUBMARINE, is described as a “novel persistent backdoor” embedded in an SQL database on the appliance. It operates with root privileges and consists of multiple artifacts, including a SQL trigger, shell scripts, and a loaded library for a Linux daemon, which together enable execution with root privileges, persistence, command and control, and cleanup. CISA warns that SUBMARINE poses a severe threat for lateral movement.
The advisory provides compromise indicators and YARA detection rules for all three malware variants. The discovery highlights the critical need for prompt action in replacing vulnerable Barracuda email gateways to protect against potential cyber threats.


