Barracuda thought it drove 0-day hackers out of customers' networks. It was wrong.
When UNC4841 infected gov't and military networks, it was just getting started.
Stay updated with breaking news from John Wolfram. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
When UNC4841 infected gov't and military networks, it was just getting started.
According to Mandiant, threat group UNC4841 dropped a second wave of backdoor malware on some victims, including government organizations, to maintain persistence for espionage purposes.
Mandiant has published new details of how a Chinese threat actor targeted high-profile users of Barracuda Networks' Email Security Gateway appliances, including government agencies of interest to Beijing's intelligence goals
New intelligence from Mandiant links exploitation of a flaw in a subset of Barracuda ESG appliances to a previously untracked China-nexus threat actor
Mandiant, which led the incident response investigation, expressed a "high degree of confidence" that a threat group linked to China is using the zero-day to target and exfiltrate email data from government officials and academics working on topics of interest to Beijing.