PACEMAKER

S1109

Malware.View on attack.mitre.org

About this malware

PACEMAKER is a credential stealer that was used by APT5 as early as 2020 including activity against US Defense Industrial Base (DIB) companies.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1003.007
Proc Filesystem

PACEMAKER has the ability to extract credentials from OS memory.

T1055.008
Ptrace System Calls

PACEMAKER can use PTRACE to attach to a targeted process to read process memory.

T1059.004
Unix Shell

PACEMAKER can use a simple bash script for execution.

T1074.001
Local Data Staging

PACEMAKER has written extracted data to `tmp/dsserver-check.statementcounters`.

T1083
File and Directory Discovery

PACEMAKER can parse `/proc/"process_name"/cmdline` to look for the string `dswsd` within the command line.

T1119
Automated Collection

PACEMAKER can enter a loop to read `/proc/` entries every 2 seconds in order to read a target application's memory.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Mandiant Pulse Secure Zero-Day April 2021 Open source
    Perez, D. et al. (2021, April 20). Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day. Retrieved February 5, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.