SLOWPULSE is a family of trojanized Pulse Connect Secure VPN authentication components used to harvest credentials and bypass authentication controls, including multi-factor authentication. It operates by modifying legitimate Pulse Secure shared objects on compromised appliances, most notably the authentication library, and inserting malicious logic into existing code paths rather than deploying as a standalone binary. Documented variants target LDAP, RADIUS, ACE, and secondary sign-in flows, forcing successful authentication when an attacker-supplied backdoor password is presented or logging submitted credentials for later theft. Some variants specifically capture ACE credentials, while others alter return values or authentication packets to make failed checks appear successful.
The malware was observed in intrusions exploiting Pulse Secure vulnerabilities, including CVE-2021-22893 and previously disclosed flaws, to gain initial access to Internet-exposed VPN appliances. After compromise, operators modified legitimate files on the appliance to maintain covert access and evade casual detection. SLOWPULSE activity has been associated with UNC2630, a cluster assessed as China-nexus and potentially linked to APT5, in campaigns targeting U.S. defense industrial base entities as well as broader government, defense, and financial-sector victims. The broader intrusion sets using related Pulse Secure malware sought long-term persistence, credential collection, and follow-on access into internal enterprise environments.
SLOWPULSE is notable for enabling authentication bypass without defeating MFA at the identity-provider level; instead, it subverts the VPN appliance’s local handling of authentication results. This allowed attackers to sidestep LDAP, RADIUS, ACE, and secondary authentication checks, and in some cases log credentials submitted during those flows. The malware therefore functioned as both an access-enablement implant and a credential theft mechanism on network edge infrastructure. Its deployment through modification of legitimate vendor files also reflects a defense-evasion and persistence strategy tailored to appliance compromises.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These attacks include using known vulnerabilities from 2019 and 2020 (CVE-2019-11510, CVE-2020-8243, and CVE-2020-8260) and a previously unknown authentication bypass vulnerability tracked as CVE-2021-22893. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
FireEye said it was tracking this activity as SlowPulse. The UNC2630 activity that was analyzed by FireEye demonstrated that successfully exploiting this vulnerability in the VPN software allowed attackers to Trojanize shared objects with malicious code to log credentials and bypass authentication flows, including multi-factor authentication requirements.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers used their perch to steal legitimate credentials, improving their chances of gaining access that’s both deep and sustained.
Here is the full list of all the MITRE ATT&CK TTP’s that FireEye/Mandiant reported as being associated with malware/groups identified in this attack: ... T1133 ...
CVE-2020-8243 (CVSS: 7.2) ... An unauthenticated threat actor could upload a customer template to perform arbitrary code execution. ... CVE-2020-8260 (CVSS: 7.2) ... an unauthenticated threat could execute arbitrary code due to a vulnerability in the admin web interface.
The main purpose of these malware tools was to circumvent authentication and to gain backdoor access.
The attackers used their perch to steal legitimate credentials, improving their chances of gaining access that’s both deep and sustained.
Here is the full list of all the MITRE ATT&CK TTP’s that FireEye/Mandiant reported as being associated with malware/groups identified in this attack: ... T1133 ...
"They modified scripts on the Pulse Secure system which enabled the malware to survive software updates and factory resets."
These attacks include using known vulnerabilities from 2019 and 2020 (CVE-2019-11510, CVE-2020-8243, and CVE-2020-8260) and a previously unknown authentication bypass vulnerability tracked as CVE-2021-22893.
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
The attackers used their perch to steal legitimate credentials, improving their chances of gaining access that’s both deep and sustained.
"They developed malware that enabled them to harvest Active Directory credentials..."
"RADIALPULSE... causes usernames, passwords and information associated with logins... to be written to the file /tmp/dsstartssh.statementcounters"; "SLOWPULSE Variant 2... logs credentials... writes them to... /home/perl/PAUS.pm".
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious code associated with Pulse Secure VPN exploitation that trojanizes shared objects to log credentials, bypass authentication flows including MFA, maintain persistence, inject web shells, and modify files.
Malware family used in Pulse Secure VPN intrusions that bypasses two-factor authentication and facilitates credential theft for deeper, sustained access.
Custom malware family associated with exploitation of Pulse Secure VPN appliances during intrusions attributed to UNC2630.
Malware used in the Pulse Connect Secure intrusion set; its operations can be detected by correlating authentication failures in LDAP/RADIUS logs with successful VPN logins, indicating tampering with authentication flows on compromised PCS appliances.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.