Malware.View on attack.mitre.org
STEADYPULSE is a web shell that infects targeted Pulse Secure VPN servers through modification of a legitimate Perl script that was used as early as 2020 including in activity against US Defense Industrial Base (DIB) entities.
| Technique | Procedure example |
|---|---|
| T1071.001 Web Protocols |
STEADYPULSE can parse web requests made to a targeted server to determine the next stage of execution. |
| T1105 Ingress Tool Transfer |
STEADYPULSE can add lines to a Perl script on a targeted server to import additional Perl modules. |
| T1132.001 Standard Encoding |
STEADYPULSE can transmit URL encoded data over C2. |
| T1140 Deobfuscate/Decode Files or Information |
STEADYPULSE can URL decode key/value pairs sent over C2. |
| T1505.003 Web Shell |
STEADYPULSE is a web shell that can enable the execution of arbitrary commands on compromised web servers. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.