ATT&CKSoftwareSLIGHTPULSE

SLIGHTPULSE

S1110

Malware.View on attack.mitre.org

About this malware

SLIGHTPULSE is a web shell that was used by APT5 as early as 2020 including against Pulse Secure VPNs at US Defense Industrial Base (DIB) entities.

Techniques used9

Procedure examples9

TechniqueProcedure example
T1005
Data from Local System

SLIGHTPULSE can read files specified on the local system.

T1059
Command and Scripting Interpreter

SLIGHTPULSE contains functionality to execute arbitrary commands passed to it.

T1071.001
Web Protocols

SLIGHTPULSE has the ability to process HTTP GET requests as a normal web server and to insert logic that will read or write files or execute commands in response to HTTP POST requests.

T1074.001
Local Data Staging

SLIGHTPULSE has piped the output from executed commands to `/tmp/1`.

T1105
Ingress Tool Transfer

RAPIDPULSE can transfer files to and from compromised hosts.

T1132.001
Standard Encoding

SLIGHTPULSE can base64 encode all incoming and outgoing C2 messages.

T1140
Deobfuscate/Decode Files or Information

SLIGHTPULSE can deobfuscate base64 encoded and RC4 encrypted C2 messages.

T1505.003
Web Shell

SLIGHTPULSE is a web shell that can read, write, and execute files on compromised servers.

T1573.001
Symmetric Cryptography

SLIGHTPULSE can RC4 encrypt all incoming and outgoing C2 messages.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Mandiant Pulse Secure Zero-Day April 2021 Open source
    Perez, D. et al. (2021, April 20). Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day. Retrieved February 5, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.