SEASPY
- Malware type
- backdoor
- Profile updated
- 2026-07-07 13:09:36
Targeted industries: technology-and-telecommunications government-and-public-sector healthcare-and-pharmaceutical
Context
According to CISA, this malware is a persistent backdoor that masquerades as a legitimate Barracuda Networks service. The malware is designed to listen to commands received from the Threat Actor’s Command-and-Control through TCP packets. When executed, the malware uses libpcap sniffer to monitor traffic for a magic packet on TCP port 25 (SMTP) and TCP port 587. It checks the network packet captured for a hard-coded string. When the right sequence of packet is captured, it establishes a TCP reverse shell to the C2 server for further exploitation. This allows the TA to execute arbitrary commands on the compromised system. The malware is based on an open-source backdoor program named "cd00r".
Detection coverage
- 4 YARA rules
Detection rules
- SIGNATURE_BASE_APT_MAL_UNC4841_SEASPY_Jun23_1 (yara-rule)
- SIGNATURE_BASE_APT_MAL_UNC4841_SEASPY_LUA_Jun23_1 (yara-rule)
- SIGNATURE_BASE_SUSP_LNX_Byteencoder_Jan25 (yara-rule)
- SIGNATURE_BASE_SUSP_LNX_Stackstring_Technique_Jan25 (yara-rule)
Reports & references
- cloud.google.com — Barracuda Esg Exploited Globally (report)
- i.blackhat.com — Asia 24 Chen Chinese Apt (report)
- youtube.com — Watch (report)
- youtube.com — Watch (report)
- sansorg.egnyte.com — 8Ekljcphpj (report)
- CISA — Mar 10454006.R2.V1.Clear (report)
- CISA — Mar 10454006.R4.V2.Clear (report)
- Mandiant — Chinese Espionage Tactics (report)
- blog.lumen.com — The J Magic Show Magic Packets And Where To Find Them (report)
- Mandiant — Barracuda Esg Exploited Globally (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Seaspy (report)
- CISA — Ar23 209B (report)
- CISA — Cisa Releases Malware Analysis Reports Barracuda Backdoors (report)