UNC2630 is a suspected China-nexus intrusion cluster associated with compromises of Pulse Secure Connect Secure VPN appliances and targeting U.S. Defense Industrial Base organizations from at least August 2020 through March 2021. The activity has been assessed as potentially tied to APT5, though that linkage is not definitive. The actor used exploitation of Pulse Secure vulnerabilities, including CVE-2021-22893 and previously disclosed flaws, to gain initial access to edge appliances. UNC2630 is notable for modifying legitimate Pulse Secure components to harvest credentials, bypass single-factor and multi-factor authentication, and maintain persistence across appliance upgrades. Malware and tooling associated with this activity include SLOWPULSE variants, which trojanize shared objects involved in authentication flows to log credentials or enable backdoor authentication bypass; webshell families such as RADIALPULSE, PULSECHECK, ATRIUM, and SLIGHTPULSE embedded into legitimate administrative web pages; PACEMAKER for persistence-related modification; and THINBLOOD for log clearing and defense evasion. Observed tradecraft included remounting appliance filesystems to permit modification, patching binaries and scripts so malicious changes survived upgrades, harvesting credentials from VPN login flows, using valid accounts for follow-on access and lateral movement, and wiping logs to reduce forensic visibility. The actor’s operations against perimeter VPN infrastructure indicate a focus on stealthy long-term access to sensitive enterprise environments, particularly within the U.S. defense sector. High-confidence reporting supports espionage-oriented objectives rather than ransomware or disruptive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.