SEASPY

Malware type
backdoor
Profile updated
2026-07-07 13:09:36

Targeted industries: technology-and-telecommunications government-and-public-sector healthcare-and-pharmaceutical

Context

According to CISA, this malware is a persistent backdoor that masquerades as a legitimate Barracuda Networks service. The malware is designed to listen to commands received from the Threat Actor’s Command-and-Control through TCP packets. When executed, the malware uses libpcap sniffer to monitor traffic for a magic packet on TCP port 25 (SMTP) and TCP port 587. It checks the network packet captured for a hard-coded string. When the right sequence of packet is captured, it establishes a TCP reverse shell to the C2 server for further exploitation. This allows the TA to execute arbitrary commands on the compromised system. The malware is based on an open-source backdoor program named "cd00r".

Detection coverage

  • 4 YARA rules

Detection rules

  • SIGNATURE_BASE_APT_MAL_UNC4841_SEASPY_Jun23_1 (yara-rule)
  • SIGNATURE_BASE_APT_MAL_UNC4841_SEASPY_LUA_Jun23_1 (yara-rule)
  • SIGNATURE_BASE_SUSP_LNX_Byteencoder_Jan25 (yara-rule)
  • SIGNATURE_BASE_SUSP_LNX_Stackstring_Technique_Jan25 (yara-rule)

Reports & references

  • cloud.google.com — Barracuda Esg Exploited Globally (report)
  • i.blackhat.com — Asia 24 Chen Chinese Apt (report)
  • youtube.com — Watch (report)
  • youtube.com — Watch (report)
  • sansorg.egnyte.com — 8Ekljcphpj (report)
  • CISA — Mar 10454006.R2.V1.Clear (report)
  • CISA — Mar 10454006.R4.V2.Clear (report)
  • Mandiant — Chinese Espionage Tactics (report)
  • blog.lumen.com — The J Magic Show Magic Packets And Where To Find Them (report)
  • Mandiant — Barracuda Esg Exploited Globally (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Seaspy (report)
  • CISA — Ar23 209B (report)
  • CISA — Cisa Releases Malware Analysis Reports Barracuda Backdoors (report)

External references