SLIGHTPULSE

MITRE ATT&CK: S1110 View on attack.mitre.org

Aliases: SLIGHTPULSE

First seen
2020-01-01 00:00:00
Malware type
webshell
Family
Malware family
Operating systems
network-devices, linux
Profile updated
2026-07-07 13:23:24

Targeted industries: defense-and-aerospace

Targeted regions: country_code:us

Context

SLIGHTPULSE is a web shell that was used by APT5 as early as 2020 including against Pulse Secure VPNs at US Defense Industrial Base (DIB) entities.

Detection coverage

  • 232 Sigma rules

Malware & tools used

  • Local Data Staging (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Web Shell (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Data from Local System (attack-pattern)
  • Command and Scripting Interpreter (attack-pattern)
  • Web Protocols (attack-pattern)
  • Symmetric Cryptography (attack-pattern)

Used by threat actors

  • APT5 (threat-actor)

Reports & references

  • Mandiant — Suspected Apt Actors Leverage Bypass Techniques Pulse Secure Zero Day (report)
  • MITRE ATT&CK — S1110 (report)

External references