ATT&CKSoftwareSTEADYPULSE

STEADYPULSE

S1112

Malware.View on attack.mitre.org

About this malware

STEADYPULSE is a web shell that infects targeted Pulse Secure VPN servers through modification of a legitimate Perl script that was used as early as 2020 including in activity against US Defense Industrial Base (DIB) entities.

Techniques used5

Procedure examples5

TechniqueProcedure example
T1071.001
Web Protocols

STEADYPULSE can parse web requests made to a targeted server to determine the next stage of execution.

T1105
Ingress Tool Transfer

STEADYPULSE can add lines to a Perl script on a targeted server to import additional Perl modules.

T1132.001
Standard Encoding

STEADYPULSE can transmit URL encoded data over C2.

T1140
Deobfuscate/Decode Files or Information

STEADYPULSE can URL decode key/value pairs sent over C2.

T1505.003
Web Shell

STEADYPULSE is a web shell that can enable the execution of arbitrary commands on compromised web servers.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. Mandiant Pulse Secure Zero-Day April 2021 Open source
    Perez, D. et al. (2021, April 20). Check Your Pulse: Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day. Retrieved February 5, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.