THINBLOOD is a log-wiping utility used in compromises of Pulse Connect Secure SSL VPN appliances. It has been associated with UNC2630 activity and with APT5-linked intrusion sets targeting organizations including U.S. Defense Industrial Base entities during the broader exploitation of Pulse Secure vulnerabilities, including campaigns tied to CVE-2021-22893 and earlier Pulse Secure flaws. THINBLOOD is part of a larger ecosystem of Pulse Secure-focused tooling that included authentication-bypass implants, credential theft utilities, web shells, and persistence mechanisms designed to survive upgrades and maintain long-term access.
Its primary function is defense evasion through anti-forensics. THINBLOOD clears relevant SSL VPN log data by removing entries that match attacker-supplied regular expressions from appliance log files under the runtime logging area. Reported behavior indicates it edits targeted access and event logs via temporary copies and file replacement operations, allowing operators to selectively erase traces of malicious authentication activity, web shell use, or other appliance interactions while preserving the surrounding log structure. This selective log tampering supports prolonged covert access and complicates incident response and forensic reconstruction.
THINBLOOD runs on Linux-based Pulse Connect Secure appliances and is best characterized as a specialized utility rather than a full-featured implant. It is typically observed post-compromise after initial access has already been established through exploitation of public-facing VPN infrastructure. In the campaigns where it appeared, operators also used credential harvesting, multifactor-authentication bypass, persistence through modified legitimate binaries and scripts, and lateral movement using stolen credentials. THINBLOOD’s role within these intrusions is to reduce visibility of those operations by removing evidence from appliance logs.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
These attacks include using known vulnerabilities from 2019 and 2020 (CVE-2019-11510, CVE-2020-8243, and CVE-2020-8260) and a previously unknown authentication bypass vulnerability tracked as CVE-2021-22893. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT5 has used the THINBLOOD utility to clear SSL VPN log files located at /home/runtime/logs.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
CVE-2020-8243 (CVSS: 7.2) ... An unauthenticated threat actor could upload a customer template to perform arbitrary code execution. ... CVE-2020-8260 (CVSS: 7.2) ... an unauthenticated threat could execute arbitrary code due to a vulnerability in the admin web interface.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Utility used to remove indicators by clearing SSL VPN log files.
Custom malware family associated with exploitation of Pulse Secure VPN appliances during intrusions attributed to UNC2630.
Malware used by UNC2630 in attacks leveraging Pulse Secure vulnerabilities to maintain long-term access and facilitate credential/data theft.
Log-wiping utility used to remove evidence from Pulse Secure appliance logs by deleting/zeroing entries matching attacker-supplied regex patterns (compiled dsclslog variant and a sed-based shell script variant).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.