ATT&CKSoftwareRAPIDPULSE

RAPIDPULSE

S1113

Malware.View on attack.mitre.org

About this malware

RAPIDPULSE is a web shell that exists as a modification to a legitimate Pulse Secure file that has been used by APT5 since at least 2021.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1005
Data from Local System

RAPIDPULSE retrieves files from the victim system via encrypted commands sent to the web shell.

T1027.013
Encrypted/Encoded File

RAPIDPULSE has the ability to RC4 encrypt and base64 encode decrypted files on compromised servers prior to writing them to stdout.

T1140
Deobfuscate/Decode Files or Information

RAPIDPULSE listens for specific HTTP query parameters in received communications. If specific parameters match, a hard-coded RC4 key is used to decrypt the HTTP query paremter hmacTime. This decrypts to a filename that is then open, read, encrypted with the same RC4 key, base64-encoded, written to standard out, then passed as a response to the HTTP request.

T1505.003
Web Shell

RAPIDPULSE is a web shell that is capable of arbitrary file read on targeted web servers to exfiltrate items of interest on the victim device.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Mandiant Pulse Secure Update May 2021 Open source
    Perez, D. et al. (2021, May 27). Re-Checking Your Pulse: Updates on Chinese APT Actors Compromising Pulse Secure VPN Devices. Retrieved February 5, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.