What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Mandiant’s account of the Barracuda Email Security Gateway (ESG) attacks points to a calculated response when defenders began disrupting the intrusion: UNC4841 changed malware and added persistence, and later used a mechanism that could carry a backdoor through restoration of an infected configuration backup. Mandiant interpreted the timing and tooling as evidence the group may have anticipated remediation—not as direct proof of what its members intended.
What was the Barracuda ESG zero-day?
CVE-2023-2868 was a remote command-injection vulnerability in how the Barracuda ESG appliance processed TAR email attachments. It affected ESG versions 5.1.3.001 through 9.2.0.006. Mandiant said an attacker could put a crafted filename inside a valid TAR archive; vulnerable code passed that unsanitized filename to Perl command execution, allowing commands to run with the appliance product’s privileges. The exploit was in archive processing, not simply in viewing an attachment that looked like an image or data file. Archives could still be valid TAR files when given extensions such as .jpg or .dat. Mandiant’s incident analysis describes the exploit and affected versions.
Mandiant traced exploitation to at least October 10, 2022. It identified SALTWATER, SEASPY and SEASIDE among the main malware families in most intrusions. The attackers used names and behaviors resembling legitimate appliance components, and in some cases searched for and exfiltrated selected data, moved from an ESG into the victim’s network, or sent email to other victim appliances. Mandiant assessed with high confidence that UNC4841 was conducting espionage in support of the People’s Republic of China; that is the firm’s analytic attribution, not independent proof of state command.
How did UNC4841 react when Barracuda began remediation?
Barracuda discovered the activity on May 19, 2023, and began releasing containment and remediation patches on May 21. Mandiant reported that UNC4841 quickly changed malware and added persistence as defenders responded. Between May 22 and 24, Mandiant observed high-frequency operations against victims in at least 16 countries. Almost a third of impacted organizations were government agencies, according to its campaign analysis; this is an approximate share, not an exact percentage. Mandiant’s June 2023 report gives the incident timeline and campaign findings.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- Rack Mount Kit for Barracuda F12
- PERFECT FIT: You can assemble your firewall or switch onto the rack with existing screws from the appliance for a perfect fit into our custom cut-outs; All connections are easily accessible from the front providing a clean look
- KEEP IT COOL: Custom model airflow cut-outs ensures that the hardware does not overheat by giving it all the breathing room it needs
- POWER: A fixed power supply secures the appliance from falling or shifting
- Product Dimensions: 2.32 in. x 18.98 in. x 8.54 in.; 1.3U/2U; Weight: 4 lbs; Part Number: RM-BC-T2
Barracuda reiterated on June 6 that impacted customers should isolate and replace compromised appliances. The sequence matters: fixing the vulnerability could prevent further exploitation through that flaw, but it did not by itself establish that malware or persistence already placed on a compromised device had been removed.
What does “prepared for remediation” mean?
The phrase describes Mandiant’s interpretation of attacker behavior. In its 2024 M-Trends account, the firm said DEPTHCHARGE appeared about one week after Barracuda’s initial public notification and was deployed more rapidly to high-value targets after replacement plans were announced. Mandiant said the timing suggested UNC4841 may have anticipated remediation and had tooling and tactics to continue operations if access was disrupted. This is an inference from timing and technical behavior, not a direct statement of the group’s intent. Mandiant’s 2024 M-Trends analysis explains that assessment.
Rank #2
- (Not 19V version. Someone may have bought it by mistake. Please Check For Compatibility With Your Unit. Thanks.) New Global 12V AC/DC Adapter Compatible with Barracuda NG NextGen Firewall F280 DNA1120A-X200 BNGF280a BNHW020 Integrated Security Appliance 12VDC 12.0V DC12V 12 Volts 12 V 12.0 VDC Power Supply Cord Cable Battery Charger Mains PSU
- Compatible with Barracuda F18 Revision B Firewall SCB-6988A-BC2 BNGF18B
- Compatible with Barracuda CloudGen Firewall F80B SCB-6988A-BC3 BNHW031 BNGF80B Security Appliance
- Tested Units. In Great Working Condition.
How configuration-backup persistence changed the picture
The later report describes a specific way DEPTHCHARGE-related persistence could survive a device replacement. The persistence could be embedded in the ESG configuration database and included in an exported backup. If that configuration were imported onto a clean replacement, it could trigger command execution and drop the backdoor. Mandiant said this happened in a small number of observed cases—not that every backup was infected or every replacement failed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What did the incident mean for remediation?
Appliance cleanup and network incident response address different risks. Barracuda’s replacement guidance concerned compromised ESG devices; Mandiant’s recommendation to investigate and hunt across affected organizations reflected evidence of persistence and, in some cases, lateral movement. The following distinctions help explain why neither simply patching nor replacing a device alone answered every question:
Rank #3
- Advanced Design, High Portability Brand New!
- Safe standard: FCC,CE, RoSH
- Replacement only, not original, but 100% compatible
- Tested Units. In Great Working Condition.
| Action or situation | What it addresses | Important limit |
|---|---|---|
| Patch the vulnerability | Closes the CVE-2023-2868 exploit route on affected software. | Does not, by itself, demonstrate that an already compromised device is free of malware or persistence. |
| Replace a compromised appliance | Barracuda advised impacted customers to discontinue use and contact its support process for a new hardware or virtual appliance. The vendor said impacted customers were offered replacements at no cost. | A configuration backup could carry DEPTHCHARGE-related persistence to a replacement in a small number of cases Mandiant observed. |
| Restore a configuration backup | Can carry settings onto a replacement device. | Because infected configurations were observed, backup restoration should be treated as a potential persistence path during incident handling, not assumed to be safe by default. |
| Investigate and hunt across the network | Checks whether access or activity extended beyond the ESG, including persistence or lateral movement. | Device replacement alone does not establish that other systems were unaffected. |
Barracuda’s notice said other products, including its SaaS email solutions, were not affected by this vulnerability. The replacement direction was specific to customers impacted by this incident, not a general recommendation for all Barracuda customers. Barracuda’s security notice contains its incident-specific instructions and product clarification.
Quick Recap
Best Value
- Compatible with Barracuda NextGen Firewall F18 BNHW025 BNGF18a 9S9-S140-101 F80 BNGF80a 9S9-S140-108 F280 BNHW026 VPN Router Security Appliance 19VDC Power Supply Charger. replaces lost or damaged power cords for these classic models
- Input 100-240V AC, 50/60Hz; supports global voltage for international use; reliable performance for home or travel
- FCC approved and safety certified; built-in overcurrent protection (OCP); short-circuit protection (SCP); overvoltage protection (OVP) for safe use
- Durable and convenient design; offers extended reach and flexibility for daily use, ideal replacement for original power supply
- Includes 1 AC Adapter + 1 Power Cord; backed by 24-month exchange warranty for peace of mind
Rank #4
- (Not 12V version. Someone may have bought it by mistake. Please Check For Compatibility With Your Unit. Thanks.) New Global 19V AC/DC Adapter Compatible with Barracuda Firewall F280 Revision B BNGF280B BNHW026 VPN Router Security Appliance 19VDC 19.0V DC19V 19 Volts 19 V 19.0 VDC Power Supply Cord Cable Battery Charger Mains PSU
- Compatible with Barracuda F18 Revision A NextGen Firewall VPN Router Security Appliance BNHW025 BNGF18a 9S9-S140-101 9S9-S140-103 9S9-S140-107
- Compatible with Barracuda NextGen Firewall F80 4-Port 1 Gbps BNHW025 BNGF80a 9S9-S140-102 9S9-S140-108
- Tested Units. In Great Working Condition.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

