Perez, D. et al. (2021, April 20). Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day. Retrieved February 5, 2024.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.007 Proc Filesystem |
MalwarePACEMAKER | PACEMAKER has the ability to extract credentials from OS memory. |
| T1005 Data from Local System |
MalwareSLIGHTPULSE | SLIGHTPULSE can read files specified on the local system. |
| T1027 Obfuscated Files or Information |
MalwareSLOWPULSE | SLOWPULSE can hide malicious code in the padding regions between legitimate functions in the Pulse Secure `libdsplibs.so` file. |
| T1055.008 Ptrace System Calls |
MalwarePACEMAKER | PACEMAKER can use PTRACE to attach to a targeted process to read process memory. |
| T1059 Command and Scripting Interpreter |
MalwareSLIGHTPULSE | SLIGHTPULSE contains functionality to execute arbitrary commands passed to it. |
| T1059.004 Unix Shell |
MalwarePACEMAKER | PACEMAKER can use a simple bash script for execution. |
| T1059.004 Unix Shell |
MalwarePULSECHECK | PULSECHECK can use Unix shell script for command execution. |
| T1070 Indicator Removal |
GroupAPT5 | APT5 has used the THINBLOOD utility to clear SSL VPN log files located at `/home/runtime/logs`. |
| T1070.004 File Deletion |
GroupAPT5 | APT5 has deleted scripts and web shells to evade detection. |
| T1071.001 Web Protocols |
MalwareSLIGHTPULSE | SLIGHTPULSE has the ability to process HTTP GET requests as a normal web server and to insert logic that will read or write files or execute commands in response to HTTP POST requests. |
| T1071.001 Web Protocols |
MalwareSTEADYPULSE | STEADYPULSE can parse web requests made to a targeted server to determine the next stage of execution. |
| T1071.001 Web Protocols |
MalwarePULSECHECK | PULSECHECK can check HTTP request headers for a specific backdoor key and if found will output the result of the command in the variable `HTTP_X_CMD.` |
| T1074.001 Local Data Staging |
MalwareSLIGHTPULSE | SLIGHTPULSE has piped the output from executed commands to `/tmp/1`. |
| T1074.001 Local Data Staging |
MalwareSLOWPULSE | SLOWPULSE can write logged ACE credentials to `/home/perl/PAUS.pm` in append mode, using the format string `%s:%s\n`. |
| T1074.001 Local Data Staging |
MalwarePACEMAKER | PACEMAKER has written extracted data to `tmp/dsserver-check.statementcounters`. |
| T1078.002 Domain Accounts |
GroupAPT5 | APT5 has used legitimate account credentials to move laterally through compromised environments. |
| T1083 File and Directory Discovery |
MalwarePACEMAKER | PACEMAKER can parse `/proc/"process_name"/cmdline` to look for the string `dswsd` within the command line. |
| T1105 Ingress Tool Transfer |
MalwareSTEADYPULSE | STEADYPULSE can add lines to a Perl script on a targeted server to import additional Perl modules. |
| T1111 Multi-Factor Authentication Interception |
MalwareSLOWPULSE | SLOWPULSE can log credentials on compromised Pulse Secure VPNs during the `DSAuth::AceAuthServer::checkUsernamePassword`ACE-2FA authentication procedure. |
| T1119 Automated Collection |
MalwarePACEMAKER | PACEMAKER can enter a loop to read `/proc/` entries every 2 seconds in order to read a target application's memory. |
| T1132.001 Standard Encoding |
MalwareSLIGHTPULSE | SLIGHTPULSE can base64 encode all incoming and outgoing C2 messages. |
| T1132.001 Standard Encoding |
MalwarePULSECHECK | PULSECHECK can base-64 encode encrypted data sent through C2. |
| T1132.001 Standard Encoding |
MalwareSTEADYPULSE | STEADYPULSE can transmit URL encoded data over C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSTEADYPULSE | STEADYPULSE can URL decode key/value pairs sent over C2. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSLIGHTPULSE | SLIGHTPULSE can deobfuscate base64 encoded and RC4 encrypted C2 messages. |
| T1190 Exploit Public-Facing Application |
GroupAPT5 | APT5 has exploited vulnerabilities in externally facing software and devices including Pulse Secure VPNs and Citrix Application Delivery Controllers. |
| T1505.003 Web Shell |
MalwarePULSECHECK | PULSECHECK is a web shell that can enable command execution on compromised servers. |
| T1505.003 Web Shell |
MalwareSTEADYPULSE | STEADYPULSE is a web shell that can enable the execution of arbitrary commands on compromised web servers. |
| T1505.003 Web Shell |
MalwareSLIGHTPULSE | SLIGHTPULSE is a web shell that can read, write, and execute files on compromised servers. |
| T1505.003 Web Shell |
GroupAPT5 | APT5 has installed multiple web shells on compromised servers including on Pulse Secure VPN appliances. |
| T1554 Compromise Host Software Binary |
GroupAPT5 | APT5 has modified legitimate binaries and scripts for Pulse Secure VPNs including the legitimate DSUpgrade.pm file to install the ATRIUM webshell for persistence. |
| T1556.004 Network Device Authentication |
MalwareSLOWPULSE | SLOWPULSE can modify LDAP and two factor authentication flows by inspecting login credentials and forcing successful authentication if the provided password matches a chosen backdoor password. |
| T1556.006 Multi-Factor Authentication |
MalwareSLOWPULSE | SLOWPULSE can insert malicious logic to bypass RADIUS and ACE two factor authentication (2FA) flows if a designated attacker-supplied password is provided. |
| T1573.001 Symmetric Cryptography |
MalwareSLIGHTPULSE | SLIGHTPULSE can RC4 encrypt all incoming and outgoing C2 messages. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.