PULSEJUMP is a Perl-based post-compromise utility used in intrusions involving Pulse Connect Secure VPN appliances. It is associated with exploitation activity against Pulse Secure devices, including campaigns tied to the UNC2717 cluster that targeted government organizations between late 2020 and early 2021. The malware is designed to harvest system information and credentials from compromised appliances, supporting follow-on access and intelligence collection.
PULSEJUMP operates on Pulse Secure appliances running a Linux-based environment and writes harvested results locally for later retrieval by the operator. Its observed role within broader intrusion sets was credential and system-information collection after attackers had already obtained access to the appliance through exploitation of Pulse Secure vulnerabilities and deployment of additional tooling. In the same campaigns, operators also used webshells, persistence mechanisms, and authentication-bypass implants to maintain long-term access and evade remediation.
PULSEJUMP has been observed alongside other Pulse Secure-focused malware families such as HARDPULSE and QUIETPULSE. Its use forms part of a broader tradecraft pattern in which attackers compromised edge VPN infrastructure, harvested credentials, bypassed multifactor authentication, and maintained durable access to victim environments. High-confidence reporting links PULSEJUMP to operations against global government targets, but available information does not support a more specific malware classification than credential-harvesting utility.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
These attacks include using known vulnerabilities from 2019 and 2020 (CVE-2019-11510, CVE-2020-8243, and CVE-2020-8260) and a previously unknown authentication bypass vulnerability tracked as CVE-2021-22893. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
CVE-2020-8243 (CVSS: 7.2) ... An unauthenticated threat actor could upload a customer template to perform arbitrary code execution. ... CVE-2020-8260 (CVSS: 7.2) ... an unauthenticated threat could execute arbitrary code due to a vulnerability in the admin web interface.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware family associated with exploitation of Pulse Secure VPN appliances during intrusions attributed to UNC2717.
Malware used by UNC2717 in PCS gateway intrusions to maintain access and support credential theft/bypass of MFA on Pulse Secure devices.
Perl script that harvests system/auth configuration information (e.g., auth servers, roles) and writes collected data to /tmp/dsactiveuser.statementcounters; also referenced alongside credential-recording artifacts in the report.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.