UNC4841 - Barracuda ESG Exploitation Indicators
Detects file indicators as seen used by UNC4841 during their Barracuda ESG zero day exploitation.
Detection logic
selection
TargetFilename|endswith:
- /11111.tar
- /aacore.sh
- /appcheck.sh
- /autoins
- /BarracudaMailService
- /etc/cron.daily/core_check.sh
- /etc/cron.daily/core.sh
- /etc/cron.hourly/aacore.sh
- /etc/cron.hourly/appcheck.sh
- /etc/cron.hourly/core.sh
- /get_fs_info.pl
- /imgdata.jpg
- /install_att_v2.tar
- /install_bvp74_auth.tar
- /install_helo.tar
- /install_reuse.tar
- /intent_helo
- /intent_reuse
- /intentbas
- /mod_attachment.lua
- /mod_content.lua
- /mod_require_helo.lua
- /mod_rtf
- /mod_sender.lua
- /mod_udp.so
- /nfsd_stub.ko
- /resize_reisertab
- /resize_risertab
- /resize2fstab
- /rverify
- /saslautchd
- /sendscd
- /snapshot.tar
- /tmp/p
- /tmp/p7
- /tmp/t
- /update_v2.sh
- /update_v31.sh
- /update_v35.sh
- /update_versionCondition
selectionRaw YAML
title: UNC4841 - Barracuda ESG Exploitation Indicators
id: 5627c337-a9b2-407a-a82d-5fd97035ff39
status: test
description: Detects file indicators as seen used by UNC4841 during their Barracuda ESG zero day exploitation.
references:
- https://www.mandiant.com/resources/blog/barracuda-esg-exploited-globally
author: Nasreddine Bencherchali (Nextron Systems)
date: 2023-06-16
modified: 2025-08-19
tags:
- attack.execution
- attack.persistence
- detection.emerging-threats
- attack.stealth
logsource:
product: linux
category: file_event
detection:
selection:
TargetFilename|endswith:
- '/11111.tar'
- '/aacore.sh'
- '/appcheck.sh'
- '/autoins'
- '/BarracudaMailService'
- '/etc/cron.daily/core_check.sh'
- '/etc/cron.daily/core.sh'
- '/etc/cron.hourly/aacore.sh'
- '/etc/cron.hourly/appcheck.sh'
- '/etc/cron.hourly/core.sh'
- '/get_fs_info.pl'
- '/imgdata.jpg'
- '/install_att_v2.tar'
- '/install_bvp74_auth.tar'
- '/install_helo.tar'
- '/install_reuse.tar'
- '/intent_helo'
- '/intent_reuse'
- '/intentbas'
# - '/mknod'
- '/mod_attachment.lua'
- '/mod_content.lua'
- '/mod_require_helo.lua'
- '/mod_rtf'
- '/mod_sender.lua'
- '/mod_udp.so'
- '/nfsd_stub.ko'
- '/resize_reisertab'
- '/resize_risertab'
- '/resize2fstab'
- '/rverify'
- '/saslautchd'
- '/sendscd'
- '/snapshot.tar'
- '/tmp/p'
- '/tmp/p7'
- '/tmp/t'
- '/update_v2.sh'
- '/update_v31.sh'
- '/update_v35.sh'
- '/update_version'
condition: selection
falsepositives:
- Unlikely
level: highFalse positives
- Unlikely
References
Similar rules
UNC4841 - Email Exfiltration File Pattern
highlinux · Same logsource category (file_event)
Pingback Backdoor File Indicators
highwindows · Same logsource category (file_event)
Potential SAP NetWeaver Webshell Creation - Linux
mediumlinux · Same logsource category (file_event)
TanStack Supply-Chain Attack File Creation Indicators - Linux
mediumlinux · Same logsource category (file_event)