PULSECHECK

MITRE ATT&CK: S1108 View on attack.mitre.org

Aliases: PULSECHECK

First seen
2020-01-01 00:00:00
Malware type
webshell
Family
Malware family
Operating systems
network-devices, linux
Profile updated
2026-07-07 13:23:20

Targeted industries: defense-and-aerospace

Targeted regions: country_code:us

Context

PULSECHECK is a web shell written in Perl that was used by APT5 as early as 2020 including against Pulse Secure VPNs at US Defense Industrial Base (DIB) companies.

Detection coverage

  • 73 Sigma rules

Malware & tools used

  • Web Protocols (attack-pattern)
  • Unix Shell (attack-pattern)
  • Web Shell (attack-pattern)
  • Standard Encoding (attack-pattern)

Used by threat actors

  • APT5 (threat-actor)

Reports & references

  • Mandiant — Suspected Apt Actors Leverage Bypass Techniques Pulse Secure Zero Day (report)
  • MITRE ATT&CK — S1108 (report)

External references