Chinese Hackers Target US, Other Govts With Barracuda Flaw
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-2868 | Unauthenticated Command Injection in Barracuda Email Security Gateway Appliances via .tar Files CVE-2023-2868 is a critical (CVSS 9.8) remote command injection vulnerability in the Barracuda Email Security Gateway (ESG) appliance form factor (models 300, 400, 600, 800 and 900), caused by incomplete input validation of user-supplied .tar archives, specifically the names of the files contained within them. An attacker can deliver a specially crafted .tar file whose internal file names are formatted so that, when the ESG processes the archive, commands are executed through Perl's qx operator. Successful exploitation yields remote command execution with the privileges of the ESG product, and in the observed campaign attackers deployed a backdoor (reported as "SUBMARINE") and persisted on compromised appliances. Only customers running ESG appliances on versions 5.1.3.001 through 9.2.0.006 are affected. Exploitation is confirmed in the wild — CISA added it to the KEV on 2023-05-26, EPSS puts 30-day exploitation probability at 87.7%, and public reporting attributes active exploitation to a Chinese-nexus espionage group (associated in headlines with Salt Typhoon) targeting government, military, and telecom victims; Barracuda's BNSF-36456 patch was applied automatically to customer appliances. Do: Verify that each ESG appliance received the automatic BNSF-36456 patch (running fixed firmware at or above 9.2.0.006's successor per vendor instructions), and check appliances for indicators of compromise, including unauthorized command activity and the "SUBMARINE" backdoor, using Barracuda's IOC guidance. Because the espionage campaign established persistence, Barracuda urged full replacement rather than patching of compromised appliances; replace any ESG showing signs of compromise and review email logs for malicious .tar attachments. Limit or monitor internet exposure of ESG management interfaces while remediation proceeds. | 9.8 | 88% | KEV |
| largetens of thousands of deployed ESG appliances (public scans show Barracuda ESGs among commonly internet-exposed email security devices); Barracuda's incident… |
Full article388 words · extracted from infosecurity-magazine.com · click to collapse
Cybersecurity firm Mandiant has unveiled the details of a sophisticated global espionage campaign allegedly orchestrated by a Chinese-nexus threat group known as UNC4841.
This group, believed to have connections with the People’s Republic of China, utilized a zero-day vulnerability (CVE-2023-2868) in Barracuda Email Security Gateway (ESG) appliances to infiltrate government and government-linked organizations worldwide.
Mandiant’s investigation revealed that the campaign spanned eight months, from October 2022 to June 2023. UNC4841, which was previously attributed to Chinese cyber-espionage, demonstrated high adaptability and sophistication in its attack techniques.
The campaign involved deploying several advanced malware families, including Skipjack, DepthCharge, Foxglove, Foxtrot and a new version of Seaspy (tracked as Seaspy V2). These malware families were selectively deployed based on the targets’ profiles, allowing the attackers to gather information, steal credentials and maintain backdoor access.
Writing in an advisory published on Tuesday, Mandiant said its investigation showed that most compromised organizations were governmental and high-tech entities, with North America being the primary geographic target.
The affected sectors included national governments, technology organizations, local governments, telecommunications providers, manufacturing entities and universities. Although the campaign affected only a limited number of ESG appliances worldwide (about 5%), the impact was significant due to the high-profile nature of the targeted organizations.
Read more on this flaw: New Submarine Backdoor Used in Barracuda Campaign
In response to the campaign, Barracuda released a patch for the ESG vulnerability on May 20 2023. The company, in collaboration with Mandiant, reported that the patch effectively mitigated the exploitation of the vulnerability. However, the attackers had deployed new malware versions after the patch’s release to maintain access in some high priority compromised environments.
“The ability to drop malware [...] which will allow the bad actors to maintain persistence even after the initial entry point is fixed, should be especially worrying for organizations impacted by this or using these appliances,” commented Erich Kron, security awareness advocate at KnowBe4.
“Trying to find and remediate potential back doors scattered across systems can be a very challenging issue for organizations. The fact that this zero-day had been exploited for [...] months makes chasing these things down even more challenging as many logs have rolled over or been deleted by now, making rogue installs of software harder to spot.”
Mandiant’s recommendations for affected victims include contacting Barracuda support and replacing compromised appliances.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/china-target-us-govts-barracuda/