ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

CISA: New Submarine Backdoor Used in Barracuda Campaign

criticalMalwareimportance 60CVE-2023-2868

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-2868
Unauthenticated Command Injection in Barracuda Email Security Gateway Appliances via .tar Files

CVE-2023-2868 is a critical (CVSS 9.8) remote command injection vulnerability in the Barracuda Email Security Gateway (ESG) appliance form factor (models 300, 400, 600, 800 and 900), caused by incomplete input validation of user-supplied .tar archives, specifically the names of the files contained within them. An attacker can deliver a specially crafted .tar file whose internal file names are formatted so that, when the ESG processes the archive, commands are executed through Perl's qx operator. Successful exploitation yields remote command execution with the privileges of the ESG product, and in the observed campaign attackers deployed a backdoor (reported as "SUBMARINE") and persisted on compromised appliances. Only customers running ESG appliances on versions 5.1.3.001 through 9.2.0.006 are affected. Exploitation is confirmed in the wild — CISA added it to the KEV on 2023-05-26, EPSS puts 30-day exploitation probability at 87.7%, and public reporting attributes active exploitation to a Chinese-nexus espionage group (associated in headlines with Salt Typhoon) targeting government, military, and telecom victims; Barracuda's BNSF-36456 patch was applied automatically to customer appliances.

Do: Verify that each ESG appliance received the automatic BNSF-36456 patch (running fixed firmware at or above 9.2.0.006's successor per vendor instructions), and check appliances for indicators of compromise, including unauthorized command activity and the "SUBMARINE" backdoor, using Barracuda's IOC guidance. Because the espionage campaign established persistence, Barracuda urged full replacement rather than patching of compromised appliances; replace any ESG showing signs of compromise and review email logs for malicious .tar attachments. Limit or monitor internet exposure of ESG management interfaces while remediation proceeds.

9.888% KEV
  • Barracuda Networks Email Security Gateway (ESG) 300 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 400 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 600 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • +2 more
largetens of thousands of deployed ESG appliances (public scans show Barracuda ESGs among commonly internet-exposed email security devices); Barracuda's incident…

Indicators of compromiseAll →

TypeIndicatorContext
ipv45.1.3.001te command injection bug affecting Barracuda ESG appliances 5.1.3.001–9.2.0.006.
Full article298 words · extracted from infosecurity-magazine.com · click to collapse

A Chinese threat actor that compromised federal networks by targeting Barracuda security appliances did so in part thanks to a newly revealed backdoor dubbed “Submarine,” a leading security agency has revealed.

The original Mandiant report on the attacks highlighted three backdoors used by the group: Seaside, Saltwater and Seaspy. However, in an update on Friday, the Cybersecurity and Infrastructure Security Agency (CISA) revealed an additional piece of backdoor malware was deployed to “establish and maintain persistence.”

Read more on the Barracuda campaign: Barracuda Zero-Day Exploited by Chinese Actor

Submarine is a “novel persistent backdoor executed with root privileges” that was hidden in a Structured Query Language (SQL) database on the targeted Barracuda Email Security Gateway (ESG) appliances, CISA said.

“Submarine comprises multiple artifacts – including a SQL trigger, shell scripts, and a loaded library for a Linux daemon – that together enable execution with root privileges, persistence, command and control, and cleanup,” the agency claimed.

“CISA also analyzed artifacts related to Submarine that contained the contents of the compromised SQL database. This malware poses a severe threat for lateral movement.”

Last month, Barracuda took the unusual decision to offer all of its affected ESG customers a replacement device, whatever their patch status.

That’s because the threat group it was tracking with Mandiant had been unusually persistent.

The vendor discovered the campaign on May 19 and released patches to contain and remediate the threat two days later. However, Chinese actor UNC4841 switched malware and deployed new persistence mechanisms to maintain access.

It then began to increase the frequency of its operations, forcing Barracuda to step in with the offer of new hardware.

UNC4841 originally gained access to victim networks via zero-day vulnerability CVE-2023-2868, which is a remote command injection bug affecting Barracuda ESG appliances 5.1.3.001–9.2.0.006.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-submarine-backdoor-barracuda/