Home/Threat Actor/UNC4841
Threat Actor

UNC4841

unc4841 · china_state_sponsored_mandiant_unc4841_barracuda_esg_zero_day_specialist · active since 2022-10

UNC4841 is Mandiant's canonical designation for a Chinese state-sponsored cyber espionage actor that exploited CVE-2023-2868 (Barracuda Email Security Gateway zero-day) in a global campaign beginning October 2022 targeting public and private organizations worldwide with specific interest in information of political or strategic interest to China per Mandiant canonical Stealth Mode blog ("Beginning in at least October 2022, suspected Chinese cyber espionage actor UNC4841 exploited a zero-day vulnerability, CVE-2023- 2868, in Barracuda Email Security Gateway ESG appliances in a campaign targeting public and private organizations worldwide")

Chinese state- sponsored attribution via Mandiant canonical UNC4841 designation May/June 2023 + Mandiant Diving Deep into UNC4841 Operations Following Barracuda ESG Zero-Day Remediation canonical coverage + Mandiant Stealth Mode blog Chinese Cyber Espionage Actors Continue to Evolve canonical coverage + Barracuda Networks canonical CVE-2023- 2868 vulnerability disclosure with replacement- not-patch recommendation + CISA + FBI Barracuda ESG advisory co-issuance.

standalone cluster paralleling apt5_unc2630 + unc3886 + unc5325 in v0.1.175 Mandiant UNC Chinese-state-sponsored network-edge-appliance zero-day specialist cluster cell.

operational target profile signature ASEAN Ministries of Foreign Affairs (MFAs) per Mandiant focused-data-exfiltration shell script evidence + signature foreign trade offices per Mandiant + signature academic research organizations per Mandiant + signature governments and organizations of high priority to China per Mandiant strategic-interest targeting methodology + signature global public and private organizations per Mandiant geographic distribution + signature Barracuda ESG operator target population.

operational attack architecture: (1) cluster-defining Barracuda Email Security Gateway specialization with extensive custom malware ecosystem developed specifically for ESG appliance compromise + persistence.

(2) cluster-defining CVE-2023-2868 Barracuda ESG remote command injection zero-day canonical exploitation allowing arbitrary system commands with elevated privileges of ESG product.

(3) cluster-defining October 2022 active-since signature establishing 7+ month pre-disclosure operational period before May 2023 Barracuda disclosure.

(4) cluster-defining custom malware ecosystem with SALTWATER + SEASIDE + SEASPY (naming conventions consistent with legitimate ESG files per Mandiant) + SEASPRAY + SKIPJACK (custom backdoor code inserted into legitimate Barracuda modules) + FOXTROT (REPTILE- derived rootkit shared tradecraft with UNC3886); (5) cluster-defining TAR file attachment exploit delivery tradecraft per Mandiant ("sent emails with specially crafted TAR file attachments that exploited CVE-2023-2868 and allowed the attackers to execute arbitrary system commands with the elevated privileges of the ESG product")

(6) cluster-defining spam-filter- caught-discourage-investigation tradecraft per Mandiant ("the subject line and body of the emails UNC4841 sent as part of this campaign were likely crafted to be caught in spam filters and discourage further investigation") with intentional-spam-filter-trigger anti-investigation methodology.

(7) cluster-defining self-signed SSL + stolen certificate C2 masquerading tradecraft per Mandiant ("UNC4841 used legitimate self-signed SSL temporary certificates that are shipped on ESG appliances for setup purposes as well as certificates stolen from victim environments to masquerade the command and control C2 traffic")

(8) cluster-defining SEASPY passive backdoor + magic-packet activation signature mirroring UNC3886 CASTLETAP FortiGate tradecraft pattern.

(9) cluster-defining ASEAN MFA + foreign trade + academic research China- strategic-interest targeting signature per Mandiant shell-script evidence ("shell scripts were uncovered that targeted email domains and users from Ministries of Foreign Affairs MFAs of ASEAN member nations as well as individuals within foreign trade offices and academic research organizations")

(10) cluster-defining aggressive remediation response signature per Mandiant ("the threat actor's aggressive response to remediation efforts and the activity going public. Following Barracuda's vulnerability disclosure and initial remediation actions, UNC4841 countered by moving rapidly to alter its malware, employ additional persistence mechanisms, and move laterally in an attempt to maintain access to compromised environments") with Barracuda appliance-replacement-rather-than-patch recommendation cluster-distinctive signature; (11) cluster-defining UNC4841-UNC3886 REPTILE- derived custom malware tradecraft overlap signature per Mandiant Diving Deep into UNC4841 blog with DRIEDMOAT (UNC3886) sharing embedded- stolen-appliance-certificate C2 encryption design with SEASPY (UNC4841)

(12) signature shell scripts targeting specific email domains + users for focused data exfiltration establishing email-content-collection operational pattern; (13) signature email exfiltration data staging tradecraft per Mandiant evidence-of-email-data-of- interest-staging signature; cluster fills the Mandiant-UNC4841-Chinese-state- sponsored + Barracuda-ESG-zero-day-specialist + CVE-2023-2868-canonical-exploitation + October- 2022-active-since + SALTWATER-SEASIDE-SEASPY- SEASPRAY-SKIPJACK-FOXTROT-custom-malware-ecosystem + ASEAN-MFA-foreign-trade-academic-research- China-strategic-interest-targeting + tar-file- attachment-exploit-delivery + spam-filter-caught- discourage-investigation-craft + self-signed-SSL- stolen-certificate-masquerading + aggressive- remediation-response-rapid-malware-alteration + UNC4841-UNC3886-REPTILE-derived-overlap position in Mandiant UNC Chinese-state-sponsored network- edge-appliance zero-day specialist cluster cell; canonical illustration of Chinese state-sponsored Barracuda Email Security Gateway zero-day specialist + CVE-2023-2868 zero-day canonical exploitation + ASEAN MFA + China strategic interest targeting methodology + TAR-file- attachment exploit delivery + spam-filter-caught anti-investigation tradecraft + aggressive remediation response + Barracuda appliance- replacement-rather-than-patch recommendation + UNC3886 REPTILE-derived custom malware overlap cited in essentially all subsequent Chinese- state-sponsored email-security-appliance industry analyses through 2022-2026 period.

china_state_sponsored_mandiant_unc4841_barracuda_esg_zero_day_specialist confidence: high 19 aliases

Profile

UNC4841 is Mandiant's canonical designation for a Chinese state-sponsored cyber espionage actor that exploited CVE-2023-2868 (Barracuda Email Security Gateway zero-day) in a global campaign beginning October 2022 targeting public and private organizations worldwide with specific interest in information of political or strategic interest to China including ASEAN Ministries of Foreign Affairs + foreign trade offices + academic research organizations. Chinese state-sponsored attribution via Mandiant canonical UNC4841 designation + extensive custom malware ecosystem analysis + multiple Mandiant blog disclosures. Standalone cluster paralleling apt5_unc2630 + unc3886 + unc5325 in v0.1.175 Mandiant UNC Chinese-state-sponsored network-edge-appliance zero-day specialist cell.

Operational target profile
  • ASEAN Ministries of Foreign Affairs.
  • Foreign trade offices.
  • Academic research organizations.
  • Governments + organizations of high priority to China strategic-interest targeting.
  • Global public and private organizations.
  • Barracuda ESG operators signature Operational attack architecture: (1) Barracuda ESG zero-day specialization (cluster-defining) (2) CVE-2023-2868 canonical exploitation (cluster-defining) (3) October 2022 active-since (cluster-defining) (4) SALTWATER + SEASIDE + SEASPY + SEASPRAY + SKIPJACK + FOXTROT custom malware ecosystem (cluster-defining) (5) ASEAN MFA + foreign trade + academic research China-strategic-interest targeting (cluster-defining) (6) TAR-file-attachment-exploit-delivery (cluster-defining) (7) Spam-filter-caught-discourage-investigation tradecraft (cluster-defining) (8) Self-signed SSL + stolen certificate C2 masquerading (cluster-defining) (9) Aggressive remediation response signature (cluster-defining) (10) UNC4841-UNC3886 REPTILE-derived overlap (cluster-defining) The cluster fills the Mandiant-UNC4841-Chinese- state-sponsored + Barracuda-ESG-zero-day- specialist + CVE-2023-2868-canonical-exploitation + October-2022-active-since + SALTWATER-SEASIDE- SEASPY-SEASPRAY-SKIPJACK-FOXTROT-custom-malware- ecosystem + ASEAN-MFA-foreign-trade-academic- research-China-strategic-interest-targeting + tar-file-attachment-exploit-delivery + spam- filter-caught-discourage-investigation-craft + self-signed-SSL-stolen-certificate-masquerading + aggressive-remediation-response-rapid-malware- alteration + UNC4841-UNC3886-REPTILE-derived- overlap position in Mandiant UNC Chinese-state- sponsored network-edge-appliance zero-day specialist cluster cell.

Aliases

19
unc4841unc 4841mandiant unc4841 trackingunc4841 chinese cyber espionage actorunc4841 prc china-nexus espionage actorunc4841 barracuda esg email security gateway specialistunc4841 cve-2023-2868 barracuda zero-dayunc4841 october 2022 active sinceunc4841 saltwater seaside seaspy seaspray skipjack custom malwareunc4841 foxtrot reptile-derived malwareunc4841 asean ministries of foreign affairs mfa targetingunc4841 foreign trade offices academic research targetingunc4841 china strategic interest email exfiltrationunc4841 aggressive remediation response signatureunc4841 tar file attachment exploit deliveryunc4841 self-signed ssl certificate masqueradingunc4841 spam filter caught discourage investigation tradecraftunc4841 unc3886 castletap reptile-derived shared tradecraftunc4841 global public private organization targeting

Notable Campaigns

11
2023UNC4841 Aggressive Remediation Response Signature (May-June 2023)
2023UNC4841-UNC3886 REPTILE-Derived Custom Malware Tradecraft Overlap Signature
2022-2026Continued Industry Reference Status (2022-2026)
2022-2023UNC4841 CVE-2023-2868 Barracuda ESG Zero-Day Canonical Exploitation
2022-2023UNC4841 TAR File Attachment Exploit Delivery Tradecraft Signature
2022-2023UNC4841 Spam-Filter-Caught-Discourage-Investigation Tradecraft Signature
2022-2023UNC4841 Custom Malware Ecosystem (SALTWATER + SEASIDE + SEASPY + SEASPRAY + SKIPJACK + FOXTROT)
2022-2023UNC4841 SEASPY Passive Backdoor + Magic-Packet Activation Signature
2022-2023UNC4841 ASEAN MFA + Foreign Trade + Academic Research China-Strategic-Interest Targeting Signature
2022-2023UNC4841 Self-Signed SSL + Stolen Certificate C2 Masquerading Signature
2022UNC4841 Origin, October 2022 Barracuda ESG Pre-Disclosure Operational Period

Attribution & Reporting

Attributed by
Mandiant (canonical UNC4841 designation May/June 2023 + ongoing tracking)Mandiant Stealth Mode blog (canonical Chinese Cyber Espionage Actors Evolve coverage)Mandiant Diving Deep into UNC4841 Operations blog (canonical CVE-2023-2868 remediation coverage)Barracuda Networks (canonical CVE-2023-2868 vulnerability disclosure + replacement-not-patch recommendation)CISA (Barracuda ESG advisory)FBI (Barracuda ESG advisory)
Key reporting
reportMandiant Stealth Mode (March 2024): Chinese Cyber Espionage Actors Continue to Evolve Tactics
reportMandiant Diving Deep into UNC4841 Operations Following Barracuda ESG Zero-Day Remediation (CVE-2023-2868)
reportBarracuda Networks (May 2023): canonical CVE-2023-2868 vulnerability disclosure + replacement-not-patch recommendation
reportCISA: Barracuda ESG advisory
reportFBI: Barracuda ESG advisory

Operational

State sponsor

UNC4841 is Mandiant's canonical designation for a Chinese state-sponsored cyber espionage actor that exploited CVE-2023-2868 (Barracuda Email Security Gateway zero-day) in a global campaign beginning October 2022 targeting public and private organizations worldwide with specific interest in information of political or strategic interest to China including ASEAN Ministries of Foreign Affairs. Per Mandiant Stealth Mode blog: "Beginning in at least October 2022, suspected Chinese cyber espionage actor UNC4841 exploited a zero-day vulnerability, CVE-2023-2868, in Barracuda Email Security Gateway (ESG) appliances in a campaign targeting public and private organizations worldwide.

" Attribution chain: (1) Mandiant canonical UNC4841 designation May/June 2023 disclosure: per Mandiant: "Mandiant has recently observed another sophisticated espionage focused China-nexus actor, UNC3886, deploying custom malware based on modified REPTILE source code
  • similar to FOXTROT [associated with UNC4841]." Cluster-defining Mandiant canonical Chinese state-sponsored attribution. (2) CVE-2023-2868 Barracuda ESG zero-day canonical exploitation: per Mandiant: "Beginning in at least October 2022, suspected Chinese cyber espionage actor UNC4841 exploited a zero- day vulnerability, CVE-2023-2868, in Barracuda Email Security Gateway (ESG) appliances." Cluster-defining CVE-2023-2868 zero-day binding signature. (3) TAR-file-attachment-exploit-delivery signature: per Mandiant: "UNC4841 sent emails with specially crafted TAR file attachments that exploited CVE-2023-2868 and allowed the attackers to execute arbitrary system commands with the elevated privileges of the ESG product." (4) Spam-filter-caught-discourage-investigation tradecraft signature: per Mandiant: "We assess that the subject line and body of the emails UNC4841 sent as part of this campaign were likely crafted to be caught in spam filters and discourage further investigation. Mandiant has observed advanced groups exploiting zero-days use this tactic in the past." (5) Custom malware family ecosystem canonical Mandiant tracking: per Mandiant:.
  • SALTWATER (named consistent with legitimate ESG files)
  • SEASIDE (named consistent with legitimate ESG files)
  • SEASPY (passive backdoor with magic-packet activation)
  • SEASPRAY (custom backdoor code inserted into legitimate Barracuda modules)
  • SKIPJACK (custom backdoor code inserted into legitimate Barracuda modules)
  • FOXTROT (REPTILE-derived rootkit also linked to UNC3886) (6) ASEAN MFA + China strategic interest email targeting signature: per Mandiant: "the actor showed specific interest in information of political or strategic interest to China. This included the global targeting of governments and organizations associated with verticals of high priority to China. Further, in the set of entities selected for focused data exfiltration, shell scripts were uncovered that targeted email domains and users from Ministries of Foreign Affairs (MFAs) of ASEAN member nations as well as individuals within foreign trade offices and academic research organizations." (7) Self-signed SSL certificate + stolen certificate C2 masquerading tradecraft: per Mandiant: "UNC4841 used legitimate self-signed SSL temporary certificates that are shipped on ESG appliances for setup purposes as well as certificates stolen from victim environments to masquerade the command and control (C2) traffic." (8) Aggressive remediation response signature: per Mandiant: "Another remarkable element of this campaign was the threat actor's aggressive response to remediation efforts and the activity going public. Following Barracuda's vulnerability disclosure and initial remediation actions, UNC4841 countered by moving rapidly to alter its malware, employ additional persistence mechanisms, and move laterally in an attempt to maintain access to compromised environments. Barracuda currently recommends replacing compromised appliances." (9) UNC4841-UNC3886 REPTILE-derived custom malware overlap signature: per Mandiant: "Other malware families deployed by UNC3886 have also shown similar characteristics to those deployed by UNC4841. For example, DRIEDMOAT is another similar passive backdoor that has been observed with an embedded certificate stolen from the compromised appliance that it uses to encrypt its C2 communications, much like the [UNC4841 SEASPY].
" Operational target profile
  • ASEAN Ministries of Foreign Affairs (MFAs) signature per Mandiant.
  • Foreign trade offices signature per Mandiant.
  • Academic research organizations signature per Mandiant.
  • Governments + organizations of high priority to China per Mandiant strategic-interest targeting.
  • Global public and private organizations per Mandiant geographic distribution.
  • Barracuda ESG operators signature appliance-target population The cluster fills the Mandiant-UNC4841-Chinese- state-sponsored + Barracuda-ESG-zero-day- specialist + CVE-2023-2868-canonical-exploitation + October-2022-active-since + SALTWATER-SEASIDE- SEASPY-SEASPRAY-SKIPJACK-FOXTROT-custom-malware- ecosystem + ASEAN-MFA-foreign-trade-academic- research-China-strategic-interest-targeting + tar-file-attachment-exploit-delivery + spam- filter-caught-discourage-investigation-craft + self-signed-SSL-stolen-certificate-masquerading + aggressive-remediation-response-rapid-malware- alteration + UNC4841-UNC3886-REPTILE-derived- overlap position in Mandiant UNC Chinese-state- sponsored network-edge-appliance zero-day specialist cluster cell.
Motivations
china_state_sponsored_cyber_espionage_intelligence_collection, barracuda_esg_email_security_gateway_specialization, asean_mfa_foreign_trade_academic_research_china_strategic_interest_targeting, cve_2023_2868_zero_day_canonical_exploitation_signature, aggressive_remediation_response_rapid_malware_alteration_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)28/60 · 46%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)17/60 · 28%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SALTWATER BARRACUDA ESG MALWARESEASIDE BARRACUDA ESG MALWARESEASPRAY BARRACUDA MODULE BACKDOORSEASPY BARRACUDA ESG PASSIVE BACKDOORSELF-SIGNED SSL TEMPORARY CERTIFICATE MASQUERADINGSHELL SCRIPTS TARGETING SPECIFIC EMAIL DOMAINS + USERS FOR DATA EXFILTRATIONSKIPJACK BARRACUDA MODULE BACKDOORSPAM FILTER CAUGHT DISCOURAGE INVESTIGATION TRADECRAFTSTOLEN VICTIM ENVIRONMENT CERTIFICATE C2 MASQUERADING

CVEs Exploited

1
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin