SLOWPULSE

MITRE ATT&CK: S1104 View on attack.mitre.org

Aliases: SLOWPULSE

First seen
2020-01-01 00:00:00
Malware type
credential-stealer, trojan
Family
Malware family
Operating systems
network-devices
Profile updated
2026-07-07 13:23:22

Targeted industries: defense-and-aerospace government-and-public-sector

Targeted regions: country_code:us

Context

SLOWPULSE is a malware that was used by APT5 as early as 2020 including against U.S. Defense Industrial Base (DIB) companies. SLOWPULSE has several variants and can modify legitimate Pulse Secure VPN files in order to log credentials and bypass single and two-factor authentication flows.

Detection coverage

  • 1 YARA rules
  • 100 Sigma rules

Malware & tools used

  • Multi-Factor Authentication (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Compromise Host Software Binary (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Network Device Authentication (attack-pattern)
  • Multi-Factor Authentication Interception (attack-pattern)

Used by threat actors

  • APT5 (threat-actor)

Detection rules

  • SIGNATURE_BASE_FE_APT_Backdoor_Linux32_SLOWPULSE_1 (yara-rule)

Reports & references

  • Mandiant — Suspected Apt Actors Leverage Bypass Techniques Pulse Secure Zero Day (report)
  • MITRE ATT&CK — S1104 (report)

External references