Skip to main content

Command Palette

Search for a command to run...

Chinese Hackers Anticipated Barracuda ESG Patch

Published
2 min readView as Markdown
Chinese Hackers Anticipated Barracuda ESG Patch
C
酷愛計算機技術Ardently Love Computer Technology 長期關註反洗錢反欺詐Long-term Focus on Anti-Money Laundering and Anti-Fraud 精通支付結算的技術、系統、流程和製度Proficient in the Technology, System, Process and Institution of Payment and Settlement

微信 smartcat9999


August 29, 2023

Chinese espionage hackers behind an eight-month campaign to hack Barracuda email security appliances intensified their focus on high-priority targets around the time the company moved to fix the zero-day flaw behind the campaign.

Within roughly a week of Barracuda's late-May public disclosures of the zero-day flaw affording Chinese hackers access to its ESG line of products, the threat actor behind the hacking spree deployed an additional backdoor to select a sliver of targets, mainly U.S. and foreign government agencies and high-tech companies, said researchers from Mandiant.

The company, brought in by Barracuda to investigate, has linked the hack to Beijing with "high confidence" and attributed the campaign to a previously unknown Chinese threat actor dubbed UNC4841.

In a Tuesday update, the company said 2.64 percent of already-compromised appliances had received the backdoor, which hackers designed to "enable infection of re-issued or clean appliances when the victim restored backup configurations from a previously compromised device." Mandiant calls the novel backdoor DepthCharge; the U.S. Cybersecurity and Infrastructure Security Agency tracks it as Submarine.

Barracuda in early June acknowledged that its deployed patch can't guarantee the removal of the sophisticated backdoor and urged owners of ESG appliances showing indicators of compromise to immediately replace the equipment. The FBI made the same entreaty in a Wednesday flash alert.

Mandiant said it also observed the Chinese hackers in late May attempting to laterally move from hacked appliances by harvesting credentials from a temporary ESG storage location. In more than one case, hackers were able to spot cleartext credentials stored within the contents of messages and use them to log in to Outlook webmail. The hackers apparently did not send email from compromised accounts, likely because they were "attempting to maintain access to compromised users' mailboxes to gather information for espionage purposes post-Barracuda remediation."

More from this blog

Penetration Test、Python、Weaponization

721 posts

微信 smartcat9999 反欺詐Anti-Fraud 反洗錢Anti-Money Laundering 反逃稅Anti-Tax Evasion 滲透測試Penetration Test 武器化Weaponization