SLIGHTPULSE is a web shell used in compromises of Pulse Connect Secure VPN appliances. It is associated with intrusion activity tracked as UNC2630, a cluster assessed in industry reporting as likely aligned with Chinese espionage objectives and potentially linked to APT5. The malware was observed in campaigns targeting organizations including U.S. Defense Industrial Base entities during the 2020–2021 Pulse Secure intrusion wave.
SLIGHTPULSE provides post-exploitation access on compromised servers by enabling attackers to read, write, and execute files, and to run arbitrary commands on the appliance. It records command execution output locally and supports Base64 encoding of inbound and outbound command-and-control traffic, indicating an effort to obfuscate operator communications and results. As a server-side implant on internet-facing VPN infrastructure, it functions as a durable access mechanism for remote administration, follow-on credential theft, and broader intrusion operations.
Within the broader Pulse Secure malware ecosystem, SLIGHTPULSE appeared alongside other appliance-focused implants and utilities used for credential harvesting, authentication bypass, persistence across upgrades, and log tampering. Its role is best characterized as a web-accessible command execution backdoor deployed after exploitation of Pulse Secure vulnerabilities, including activity contemporaneous with exploitation of CVE-2021-22893 and older Pulse Secure flaws. It targets Linux-based Pulse Connect Secure appliances rather than general-purpose desktop systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
These attacks include using known vulnerabilities from 2019 and 2020 (CVE-2019-11510, CVE-2020-8243, and CVE-2020-8260) and a previously unknown authentication bypass vulnerability tracked as CVE-2021-22893. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"UNC2630 - SLOWPULSE, RADIALPULSE, THINBLOOD, ATRIUM, PACEMAKER, SLIGHTPULSE, and PULSECHECK"
18 distinct techniques documented for this family, organized by ATT&CK tactic.
CVE-2020-8243 (CVSS: 7.2) ... An unauthenticated threat actor could upload a customer template to perform arbitrary code execution. ... CVE-2020-8260 (CVSS: 7.2) ... an unauthenticated threat could execute arbitrary code due to a vulnerability in the admin web interface.
The content repeatedly describes threat actors and malware collecting, stealing, identifying, copying, or staging files, documents, credentials, logs, databases, and other information from compromised hosts or local systems.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
"ReadFile... opens it for read... sent back..."; "WriteFile... filename... file data... written"; "HARDPULSE... matched against get and put which will read/write arbitrary files".
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pulse Secure appliance webshell used to maintain access; additionally referenced as being hidden from integrity checks by actor persistence logic.
Custom malware family associated with exploitation of Pulse Secure VPN appliances during intrusions attributed to UNC2630.
Malware used by UNC2630 in PCS intrusions; associated tradecraft includes persistence across updates/resets and credential harvesting.
Webshell embedded into meeting_testjs.cgi supporting arbitrary file read/write and command execution; uses base64 + RC4 for request/response data and writes command output to /tmp/1.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.