Perez, D. et al. (2021, May 27). Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices. Retrieved February 5, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
GroupAPT5 | APT5 has used the Task Manager process to target LSASS process memory in order to obtain NTLM password hashes. APT5 has also dumped clear text passwords and hashes from memory using Mimikatz hosted through an RDP mapped drive. |
| T1003.002 Security Account Manager |
GroupAPT5 | APT5 has copied and exfiltrated the SAM Registry hive from targeted systems. |
| T1005 Data from Local System |
MalwareRAPIDPULSE | RAPIDPULSE retrieves files from the victim system via encrypted commands sent to the web shell. |
| T1021.001 Remote Desktop Protocol |
GroupAPT5 | APT5 has moved laterally throughout victim environments using RDP. |
| T1021.004 SSH |
GroupAPT5 | APT5 has used SSH for lateral movement in compromised environments including for enabling access to ESXi host servers. |
| T1027.013 Encrypted/Encoded File |
MalwareRAPIDPULSE | RAPIDPULSE has the ability to RC4 encrypt and base64 encode decrypted files on compromised servers prior to writing them to stdout. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupAPT5 | APT5 has named exfiltration archives to mimic Windows Updates at times using filenames with a `KB<digits>.zip` pattern. |
| T1049 System Network Connections Discovery |
GroupAPT5 | APT5 has used the BLOODMINE utility to collect data on web requests from Pulse Secure Connect logs. |
| T1055 Process Injection |
GroupAPT5 | APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to alter its functionality. |
| T1057 Process Discovery |
GroupAPT5 | APT5 has used Windows-based utilities to carry out tasks including tasklist.exe. |
| T1059.001 PowerShell |
GroupAPT5 | APT5 has used PowerShell to accomplish tasks within targeted environments. |
| T1059.003 Windows Command Shell |
GroupAPT5 | APT5 has used cmd.exe for execution on compromised systems. |
| T1070 Indicator Removal |
GroupAPT5 | APT5 has used the THINBLOOD utility to clear SSL VPN log files located at `/home/runtime/logs`. |
| T1070.003 Clear Command History |
GroupAPT5 | APT5 has cleared the command history on targeted ESXi servers. |
| T1070.004 File Deletion |
GroupAPT5 | APT5 has deleted scripts and web shells to evade detection. |
| T1070.006 Timestomp |
GroupAPT5 | APT5 has modified file timestamps. |
| T1074.001 Local Data Staging |
GroupAPT5 | APT5 has staged data on compromised systems prior to exfiltration often in `C:\Users\Public`. |
| T1078.004 Cloud Accounts |
GroupAPT5 | APT5 has accessed Microsoft M365 cloud environments using stolen credentials. |
| T1083 File and Directory Discovery |
GroupAPT5 | APT5 has used the BLOODMINE utility to discover files with .css, .jpg, .png, .gif, .ico, .js, and .jsp extensions in Pulse Secure Connect logs. |
| T1098.007 Additional Local or Domain Groups |
GroupAPT5 | APT5 has created their own accounts with Local Administrator privileges to maintain access to systems with short-cycle credential rotation. |
| T1105 Ingress Tool Transfer |
MalwareSLIGHTPULSE | RAPIDPULSE can transfer files to and from compromised hosts. |
| T1136.001 Local Account |
GroupAPT5 | APT5 has created Local Administrator accounts to maintain access to systems with short-cycle credential rotation. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareRAPIDPULSE | RAPIDPULSE listens for specific HTTP query parameters in received communications. If specific parameters match, a hard-coded RC4 key is used to decrypt the HTTP query paremter |
| T1190 Exploit Public-Facing Application |
GroupAPT5 | APT5 has exploited vulnerabilities in externally facing software and devices including Pulse Secure VPNs and Citrix Application Delivery Controllers. |
| T1505.003 Web Shell |
GroupAPT5 | APT5 has installed multiple web shells on compromised servers including on Pulse Secure VPN appliances. |
| T1505.003 Web Shell |
MalwareRAPIDPULSE | RAPIDPULSE is a web shell that is capable of arbitrary file read on targeted web servers to exfiltrate items of interest on the victim device. |
| T1554 Compromise Host Software Binary |
GroupAPT5 | APT5 has modified legitimate binaries and scripts for Pulse Secure VPNs including the legitimate DSUpgrade.pm file to install the ATRIUM webshell for persistence. |
| T1554 Compromise Host Software Binary |
MalwareSLOWPULSE | SLOWPULSE is applied in compromised environments through modifications to legitimate Pulse Secure files. |
| T1560.001 Archive via Utility |
GroupAPT5 | APT5 has used the JAR/ZIP file format for exfiltrated files. |
| T1654 Log Enumeration |
GroupAPT5 | APT5 has used the BLOODMINE utility to parse and extract information from Pulse Secure Connect logs. |
| T1685 Disable or Modify Tools |
GroupAPT5 | APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to prevent certain log events from occurring. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.