ATT&CKReferencesMandiant Pulse Secure Zero-Day April 2021

Mandiant Pulse Secure Zero-Day April 2021

Perez, D. et al. (2021, April 20). Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day. Retrieved February 5, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software5

Campaigns0

None recorded.

Procedure examples34

TechniqueUsed byProcedure example
T1003.007
Proc Filesystem
MalwarePACEMAKER

PACEMAKER has the ability to extract credentials from OS memory.

T1005
Data from Local System
MalwareSLIGHTPULSE

SLIGHTPULSE can read files specified on the local system.

T1027
Obfuscated Files or Information
MalwareSLOWPULSE

SLOWPULSE can hide malicious code in the padding regions between legitimate functions in the Pulse Secure `libdsplibs.so` file.

T1055.008
Ptrace System Calls
MalwarePACEMAKER

PACEMAKER can use PTRACE to attach to a targeted process to read process memory.

T1059
Command and Scripting Interpreter
MalwareSLIGHTPULSE

SLIGHTPULSE contains functionality to execute arbitrary commands passed to it.

T1059.004
Unix Shell
MalwarePACEMAKER

PACEMAKER can use a simple bash script for execution.

T1059.004
Unix Shell
MalwarePULSECHECK

PULSECHECK can use Unix shell script for command execution.

T1070
Indicator Removal
GroupAPT5

APT5 has used the THINBLOOD utility to clear SSL VPN log files located at `/home/runtime/logs`.

T1070.004
File Deletion
GroupAPT5

APT5 has deleted scripts and web shells to evade detection.

T1071.001
Web Protocols
MalwareSLIGHTPULSE

SLIGHTPULSE has the ability to process HTTP GET requests as a normal web server and to insert logic that will read or write files or execute commands in response to HTTP POST requests.

T1071.001
Web Protocols
MalwareSTEADYPULSE

STEADYPULSE can parse web requests made to a targeted server to determine the next stage of execution.

T1071.001
Web Protocols
MalwarePULSECHECK

PULSECHECK can check HTTP request headers for a specific backdoor key and if found will output the result of the command in the variable `HTTP_X_CMD.`

T1074.001
Local Data Staging
MalwareSLIGHTPULSE

SLIGHTPULSE has piped the output from executed commands to `/tmp/1`.

T1074.001
Local Data Staging
MalwareSLOWPULSE

SLOWPULSE can write logged ACE credentials to `/home/perl/PAUS.pm` in append mode, using the format string `%s:%s\n`.

T1074.001
Local Data Staging
MalwarePACEMAKER

PACEMAKER has written extracted data to `tmp/dsserver-check.statementcounters`.

T1078.002
Domain Accounts
GroupAPT5

APT5 has used legitimate account credentials to move laterally through compromised environments.

T1083
File and Directory Discovery
MalwarePACEMAKER

PACEMAKER can parse `/proc/"process_name"/cmdline` to look for the string `dswsd` within the command line.

T1105
Ingress Tool Transfer
MalwareSTEADYPULSE

STEADYPULSE can add lines to a Perl script on a targeted server to import additional Perl modules.

T1111
Multi-Factor Authentication Interception
MalwareSLOWPULSE

SLOWPULSE can log credentials on compromised Pulse Secure VPNs during the `DSAuth::AceAuthServer::checkUsernamePassword`ACE-2FA authentication procedure.

T1119
Automated Collection
MalwarePACEMAKER

PACEMAKER can enter a loop to read `/proc/` entries every 2 seconds in order to read a target application's memory.

T1132.001
Standard Encoding
MalwareSLIGHTPULSE

SLIGHTPULSE can base64 encode all incoming and outgoing C2 messages.

T1132.001
Standard Encoding
MalwarePULSECHECK

PULSECHECK can base-64 encode encrypted data sent through C2.

T1132.001
Standard Encoding
MalwareSTEADYPULSE

STEADYPULSE can transmit URL encoded data over C2.

T1140
Deobfuscate/Decode Files or Information
MalwareSTEADYPULSE

STEADYPULSE can URL decode key/value pairs sent over C2.

T1140
Deobfuscate/Decode Files or Information
MalwareSLIGHTPULSE

SLIGHTPULSE can deobfuscate base64 encoded and RC4 encrypted C2 messages.

T1190
Exploit Public-Facing Application
GroupAPT5

APT5 has exploited vulnerabilities in externally facing software and devices including Pulse Secure VPNs and Citrix Application Delivery Controllers.

T1505.003
Web Shell
MalwarePULSECHECK

PULSECHECK is a web shell that can enable command execution on compromised servers.

T1505.003
Web Shell
MalwareSTEADYPULSE

STEADYPULSE is a web shell that can enable the execution of arbitrary commands on compromised web servers.

T1505.003
Web Shell
MalwareSLIGHTPULSE

SLIGHTPULSE is a web shell that can read, write, and execute files on compromised servers.

T1505.003
Web Shell
GroupAPT5

APT5 has installed multiple web shells on compromised servers including on Pulse Secure VPN appliances.

T1554
Compromise Host Software Binary
GroupAPT5

APT5 has modified legitimate binaries and scripts for Pulse Secure VPNs including the legitimate DSUpgrade.pm file to install the ATRIUM webshell for persistence.

T1556.004
Network Device Authentication
MalwareSLOWPULSE

SLOWPULSE can modify LDAP and two factor authentication flows by inspecting login credentials and forcing successful authentication if the provided password matches a chosen backdoor password.

T1556.006
Multi-Factor Authentication
MalwareSLOWPULSE

SLOWPULSE can insert malicious logic to bypass RADIUS and ACE two factor authentication (2FA) flows if a designated attacker-supplied password is provided.

T1573.001
Symmetric Cryptography
MalwareSLIGHTPULSE

SLIGHTPULSE can RC4 encrypt all incoming and outgoing C2 messages.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.