HomeSecurityFBI: Patched Barracuda ESG appliances still being compromised

FBI: Patched Barracuda ESG appliances still being compromised

The FBI warns of the risk of hackers still attacking Barracuda ESG appliances that have been updated.

See also: Discord: Notifies users affected by previous data breach

FBI: Patched Barracuda ESG appliances still being compromised

The Federal Bureau of Investigation has warned that updates for a critical remote command injection vulnerability in the Barracuda Email Security Gateway (ESG) are “ineffective” and that patched appliances continue to be compromised in attacks.

Recorded as CVE-2023-2868, the vulnerability was first exploited in October 2022 to introduce a backdoor into ESG devices and steal data from the compromised systems.

The attackers used previously unknown malware, SeaSpy and Saltwater, as well as a malicious tool, SeaSide, to install reverse shells for remote access.

CISA later released further details about the Submariner and Whirlpool malware used in the same attacks. The US Cybersecurity Agency also added this flaw to its list of actively exploited vulnerabilities in the internet environment on May 27, warning federal authorities to check networks for evidence of a breach.

See also: New Whiffy Recon malware detected: What are its characteristics?

Although Barracuda patched all devices and closed off attackers' access to the compromised devices on May 20, one day after the bug was discovered, on June 7 it warned all customers that they should immediately replace all affected devices, presumably because it could not guarantee the complete removal of the malware used in the attacks.

Later, Mandiant linked the data theft campaign targeting Barracuda ESG appliances and using CVE-2023-2868 exploits to the UNC4841 group, described as a suspected pro- China.

Barracuda ESG

See also: Metro Bank sounds the alarm over increase in malware attacks

The FBI is also warning Barracuda customers to replace their appliances

The FBI is reinforcing Barracuda's warning to customers that they should urgently isolate and replace hacked devices because Chinese hackers are still actively exploiting the vulnerability and even devices with updated software are at risk due to "inadequate" patching.

Additionally, the company recommends that Barracuda customers investigate networks for potential additional breaches, looking for outbound connections to IP addresses included in the list of indicators of compromise (IOCs) shared in the advisory.

Users who used privileged enterprise credentials with Barracuda devices (e.g. Active Directory Domain Admin) were also reminded to revoke and renew them to prevent attackers from attempting to maintain network persistence .

Barracuda says its security products are used by over 200,000 organizations worldwide, including well-known companies such as Samsung, Delta Airlines, Mitsubishi , and Kraft Heinz.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS