SLOWPULSE

S1104

Malware.View on attack.mitre.org

About this malware

SLOWPULSE is a malware that was used by APT5 as early as 2020 including against U.S. Defense Industrial Base (DIB) companies. SLOWPULSE has several variants and can modify legitimate Pulse Secure VPN files in order to log credentials and bypass single and two-factor authentication flows.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027
Obfuscated Files or Information

SLOWPULSE can hide malicious code in the padding regions between legitimate functions in the Pulse Secure `libdsplibs.so` file.

T1074.001
Local Data Staging

SLOWPULSE can write logged ACE credentials to `/home/perl/PAUS.pm` in append mode, using the format string `%s:%s\n`.

T1111
Multi-Factor Authentication Interception

SLOWPULSE can log credentials on compromised Pulse Secure VPNs during the `DSAuth::AceAuthServer::checkUsernamePassword`ACE-2FA authentication procedure.

T1554
Compromise Host Software Binary

SLOWPULSE is applied in compromised environments through modifications to legitimate Pulse Secure files.

T1556.004
Network Device Authentication

SLOWPULSE can modify LDAP and two factor authentication flows by inspecting login credentials and forcing successful authentication if the provided password matches a chosen backdoor password.

T1556.006
Multi-Factor Authentication

SLOWPULSE can insert malicious logic to bypass RADIUS and ACE two factor authentication (2FA) flows if a designated attacker-supplied password is provided.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Mandiant Pulse Secure Zero-Day April 2021 Open source
    Perez, D. et al. (2021, April 20). Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day. Retrieved February 5, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.