Netskope Threat Labs

Seaspy

ATP Sandbox Adv. Heuristics

Seaspy is a persistent backdoor that masquerades as a legitimate Barracuda Networks service and listens for commands in TCP packets on SMTP ports. It uses libpcap to monitor traffic for a hard-coded magic packet sequence and then establishes a TCP reverse shell to the command and control server, and its design derives from the open source cd00r backdoor.

First seen
June 2023
Last seen
September 2026
SeaSpy
Alert Name
Linux.Trojan.Seaspy
Linux.Trojan.SeaSpy