Whirlpool Malware Follows in Barracuda's Footsteps

danger malware ransomware

The US cybersecurity and infrastructure security agency (CISA) has identified sophisticated and prolonged Advanced Persistent Threat (APT) attacks aimed at exploiting a previous zero-day vulnerability in Barracuda email security gateway (ESG) devices. The vulnerability, as detailed in a CISA alert, was leveraged to implant malicious software payloads, specifically Seapsy and Whirlpool backdoors, onto the compromised appliances.

Seapsy functions as a persistent and concealed threat, camouflaging itself as a legitimate Barracuda service named "BarracudaMailService." This façade allows threat actors to execute unauthorized commands on the ESG appliance. On the other hand, Whirlpool backdooring represents a fresh tactic employed by attackers. It entails creating a secure reverse communication channel to a Command-and-Control (C2) server using a Transport Layer Security (TLS) reverse shell.

Whirlpool Uses Vulnerability to Infiltrate

The CISA alert confirms that it obtained samples of the malicious software, including the Seapsy and Whirlpool backdoors. The compromise of the device was facilitated by exploiting the Barracuda ESG vulnerability, which is identified as CVE-2023-2868. This vulnerability enables remote command execution on ESG appliances operating versions 5.1.3.001 through 9.2.0.006.

Whirlpool, which appears as a 32-bit executable and linkable format (ELF), requires two arguments (C2 IP and port number) from a module to establish the TLS reverse shell, allowing secure communication between the compromised system and the attacker's controlled server. Regrettably, the specific module that conveys these arguments for analysis by CISA remains unavailable.

In addition to Seapsy and Whirlpool, other instances of backdoor exploitation within Barracuda ESG systems encompass Saltwater, Submarine, and Seaside.

August 18, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.