Malware.View on attack.mitre.org
SLIGHTPULSE is a web shell that was used by APT5 as early as 2020 including against Pulse Secure VPNs at US Defense Industrial Base (DIB) entities.
| Technique | Procedure example |
|---|---|
| T1005 Data from Local System |
SLIGHTPULSE can read files specified on the local system. |
| T1059 Command and Scripting Interpreter |
SLIGHTPULSE contains functionality to execute arbitrary commands passed to it. |
| T1071.001 Web Protocols |
SLIGHTPULSE has the ability to process HTTP GET requests as a normal web server and to insert logic that will read or write files or execute commands in response to HTTP POST requests. |
| T1074.001 Local Data Staging |
SLIGHTPULSE has piped the output from executed commands to `/tmp/1`. |
| T1105 Ingress Tool Transfer |
RAPIDPULSE can transfer files to and from compromised hosts. |
| T1132.001 Standard Encoding |
SLIGHTPULSE can base64 encode all incoming and outgoing C2 messages. |
| T1140 Deobfuscate/Decode Files or Information |
SLIGHTPULSE can deobfuscate base64 encoded and RC4 encrypted C2 messages. |
| T1505.003 Web Shell |
SLIGHTPULSE is a web shell that can read, write, and execute files on compromised servers. |
| T1573.001 Symmetric Cryptography |
SLIGHTPULSE can RC4 encrypt all incoming and outgoing C2 messages. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.