UNC4841 — APT Profile
UNC4841 exploited a Barracuda ESG zero-day vulnerability to install persistent backdoors on government and technology organization email gateways globally.Tools & malware
- DEPTHCHARGE Backdoor
- FOXGLOVE Loader
- FOXTROT Backdoor
- fscan Tool
- SALTWATER Backdoor
- SANDBAR Tool
- SEASIDE Backdoor
- SEASPRAY Loader
- SEASPY Backdoor
- SKIPJACK Backdoor
- WHIRLPOOL Backdoor
Vendor research
- Barracuda ESG Zero-Day Vulnerability (CVE-2023-2868) Exploited Globally by Aggressive and Skilled Actor, Suspected Links to China Mandiant (Google Cloud)
- Diving Deep into UNC4841 Operations Following Barracuda ESG Zero-Day Remediation (CVE-2023-2868) Mandiant (Google Cloud)
Countries linked to this actor
- Belgium targets