ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

CISA: New Whirlpool Backdoor Used in Barracuda ESG Campaign

criticalMalwareimportance 60CVE-2023-2868

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-2868
Unauthenticated Command Injection in Barracuda Email Security Gateway Appliances via .tar Files

CVE-2023-2868 is a critical (CVSS 9.8) remote command injection vulnerability in the Barracuda Email Security Gateway (ESG) appliance form factor (models 300, 400, 600, 800 and 900), caused by incomplete input validation of user-supplied .tar archives, specifically the names of the files contained within them. An attacker can deliver a specially crafted .tar file whose internal file names are formatted so that, when the ESG processes the archive, commands are executed through Perl's qx operator. Successful exploitation yields remote command execution with the privileges of the ESG product, and in the observed campaign attackers deployed a backdoor (reported as "SUBMARINE") and persisted on compromised appliances. Only customers running ESG appliances on versions 5.1.3.001 through 9.2.0.006 are affected. Exploitation is confirmed in the wild — CISA added it to the KEV on 2023-05-26, EPSS puts 30-day exploitation probability at 87.7%, and public reporting attributes active exploitation to a Chinese-nexus espionage group (associated in headlines with Salt Typhoon) targeting government, military, and telecom victims; Barracuda's BNSF-36456 patch was applied automatically to customer appliances.

Do: Verify that each ESG appliance received the automatic BNSF-36456 patch (running fixed firmware at or above 9.2.0.006's successor per vendor instructions), and check appliances for indicators of compromise, including unauthorized command activity and the "SUBMARINE" backdoor, using Barracuda's IOC guidance. Because the espionage campaign established persistence, Barracuda urged full replacement rather than patching of compromised appliances; replace any ESG showing signs of compromise and review email logs for malicious .tar attachments. Limit or monitor internet exposure of ESG management interfaces while remediation proceeds.

9.888% KEV
  • Barracuda Networks Email Security Gateway (ESG) 300 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 400 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 600 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • +2 more
largetens of thousands of deployed ESG appliances (public scans show Barracuda ESGs among commonly internet-exposed email security devices); Barracuda's incident…
Full article311 words · extracted from infosecurity-magazine.com · click to collapse

Security researchers have discovered a third novel backdoor that was used in attacks on users of Barracuda ESG appliances recently.

The US Cybersecurity and Infrastructure Security Agency (CISA) has released a new advisory detailing the malware, dubbed “Whirlpool.”

It claimed the backdoor established a TLS reverse shell to a command-and-control (C2) server.

“This artifact is a 32-bit ELF file that has been identified as a malware variant named ‘Whirlpool,’” the document noted.

“The malware takes two arguments (C2 IP and port number) from a module to establish a Transport Layer Security (TLS) reverse shell. The module that passes the arguments was not available for analysis.”

This comes after a separate CISA update at the end of July in which the agency revealed a separate backdoor, dubbed “Submarine,” had also been used in the campaign. That one was described as “a novel persistent backdoor executed with root privileges.”

Security vendor Barracuda Networks took the unusual decision back in June to offer all users of its Email Security Gateway (ESG) appliance a replacement device, following the discovery of a sophisticated cyber-espionage campaign.

Read more on the campaign: Barracuda Urges Swift Replacement of Vulnerable ESG Appliances

The attacks exploited zero-day vulnerability, tracked as CVE-2023-2868, and had been ongoing since October 2022, the vendor claimed.  

It was subsequently revealed by Mandiant that the threat actor was a likely Chinese APT group (UNC4841). Barracuda discovered the attacks on May 19 and patched the zero-day two days later, but the group switched malware and deployed new persistence mechanisms to maintain access.

It then upped the frequency of its attacks and targeted victims in 16 countries over the succeeding two days. That’s when Barracuda took the decision to urge all customers to replace their appliance.

The group also used malware known as Seaside as well as the previously undiscovered Saltwater and Seaspy variants in the attacks.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/whirlpool-backdoor-barracuda-esg/