Seriously Risky Business Newsletter
June 22, 2023
China's Barracuda Hacks Were Just Plain Rude
Presented by

Policy & Intelligence
The polite thing to do when your APT operation is discovered by your adversaries is to pack up, go home, and ready your next campaign. What you shouldn't do is escalate in response to discovery, dig in, and turn thousands of expensive email gateway appliances into boat anchors.
But this is exactly what a Chinese APT group did in response to one of its recent campaigns being rumbled.
Last week, Mandiant published a report attributing a recent "wide-ranging campaign" exploiting a Barracuda Email Security Gateway (ESG) vulnerability to a PRC cyberespionage actor it tracks as UNC4841.