ATT&CKReferencesMandiant Pulse Secure Update May 2021

Mandiant Pulse Secure Update May 2021

Perez, D. et al. (2021, May 27). Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices. Retrieved February 5, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples31

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupAPT5

APT5 has used the Task Manager process to target LSASS process memory in order to obtain NTLM password hashes. APT5 has also dumped clear text passwords and hashes from memory using Mimikatz hosted through an RDP mapped drive.

T1003.002
Security Account Manager
GroupAPT5

APT5 has copied and exfiltrated the SAM Registry hive from targeted systems.

T1005
Data from Local System
MalwareRAPIDPULSE

RAPIDPULSE retrieves files from the victim system via encrypted commands sent to the web shell.

T1021.001
Remote Desktop Protocol
GroupAPT5

APT5 has moved laterally throughout victim environments using RDP.

T1021.004
SSH
GroupAPT5

APT5 has used SSH for lateral movement in compromised environments including for enabling access to ESXi host servers.

T1027.013
Encrypted/Encoded File
MalwareRAPIDPULSE

RAPIDPULSE has the ability to RC4 encrypt and base64 encode decrypted files on compromised servers prior to writing them to stdout.

T1036.005
Match Legitimate Resource Name or Location
GroupAPT5

APT5 has named exfiltration archives to mimic Windows Updates at times using filenames with a `KB<digits>.zip` pattern.

T1049
System Network Connections Discovery
GroupAPT5

APT5 has used the BLOODMINE utility to collect data on web requests from Pulse Secure Connect logs.

T1055
Process Injection
GroupAPT5

APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to alter its functionality.

T1057
Process Discovery
GroupAPT5

APT5 has used Windows-based utilities to carry out tasks including tasklist.exe.

T1059.001
PowerShell
GroupAPT5

APT5 has used PowerShell to accomplish tasks within targeted environments.

T1059.003
Windows Command Shell
GroupAPT5

APT5 has used cmd.exe for execution on compromised systems.

T1070
Indicator Removal
GroupAPT5

APT5 has used the THINBLOOD utility to clear SSL VPN log files located at `/home/runtime/logs`.

T1070.003
Clear Command History
GroupAPT5

APT5 has cleared the command history on targeted ESXi servers.

T1070.004
File Deletion
GroupAPT5

APT5 has deleted scripts and web shells to evade detection.

T1070.006
Timestomp
GroupAPT5

APT5 has modified file timestamps.

T1074.001
Local Data Staging
GroupAPT5

APT5 has staged data on compromised systems prior to exfiltration often in `C:\Users\Public`.

T1078.004
Cloud Accounts
GroupAPT5

APT5 has accessed Microsoft M365 cloud environments using stolen credentials.

T1083
File and Directory Discovery
GroupAPT5

APT5 has used the BLOODMINE utility to discover files with .css, .jpg, .png, .gif, .ico, .js, and .jsp extensions in Pulse Secure Connect logs.

T1098.007
Additional Local or Domain Groups
GroupAPT5

APT5 has created their own accounts with Local Administrator privileges to maintain access to systems with short-cycle credential rotation.

T1105
Ingress Tool Transfer
MalwareSLIGHTPULSE

RAPIDPULSE can transfer files to and from compromised hosts.

T1136.001
Local Account
GroupAPT5

APT5 has created Local Administrator accounts to maintain access to systems with short-cycle credential rotation.

T1140
Deobfuscate/Decode Files or Information
MalwareRAPIDPULSE

RAPIDPULSE listens for specific HTTP query parameters in received communications. If specific parameters match, a hard-coded RC4 key is used to decrypt the HTTP query paremter hmacTime. This decrypts to a filename that is then open, read, encrypted with the same RC4 key, base64-encoded, written to standard out, then passed as a response to the HTTP request.

T1190
Exploit Public-Facing Application
GroupAPT5

APT5 has exploited vulnerabilities in externally facing software and devices including Pulse Secure VPNs and Citrix Application Delivery Controllers.

T1505.003
Web Shell
GroupAPT5

APT5 has installed multiple web shells on compromised servers including on Pulse Secure VPN appliances.

T1505.003
Web Shell
MalwareRAPIDPULSE

RAPIDPULSE is a web shell that is capable of arbitrary file read on targeted web servers to exfiltrate items of interest on the victim device.

T1554
Compromise Host Software Binary
GroupAPT5

APT5 has modified legitimate binaries and scripts for Pulse Secure VPNs including the legitimate DSUpgrade.pm file to install the ATRIUM webshell for persistence.

T1554
Compromise Host Software Binary
MalwareSLOWPULSE

SLOWPULSE is applied in compromised environments through modifications to legitimate Pulse Secure files.

T1560.001
Archive via Utility
GroupAPT5

APT5 has used the JAR/ZIP file format for exfiltrated files.

T1654
Log Enumeration
GroupAPT5

APT5 has used the BLOODMINE utility to parse and extract information from Pulse Secure Connect logs.

T1685
Disable or Modify Tools
GroupAPT5

APT5 has used the CLEANPULSE utility to insert command line strings into a targeted process to prevent certain log events from occurring.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.