PULSECHECK is a Perl-based web shell used in compromises of Pulse Connect Secure VPN appliances. It was observed in intrusion activity exploiting Pulse Secure vulnerabilities, including campaigns associated with the UNC2630 cluster, which targeted U.S. Defense Industrial Base organizations from 2020 into 2021 and has been assessed as likely China-nexus with possible ties to APT5. PULSECHECK was deployed alongside other Pulse Secure-focused malware families such as SLOWPULSE, RADIALPULSE, PACEMAKER, THINBLOOD, ATRIUM, and SLIGHTPULSE.
The malware enables arbitrary command execution on compromised servers. It is triggered through HTTP POST requests and uses custom HTTP headers to authenticate access, receive commands, and supply an encryption key. Command output is returned to the operator after RC4 encryption and Base64 encoding, reflecting an effort to obfuscate command-and-control traffic. Its role is consistent with post-exploitation access on already-compromised edge infrastructure rather than commodity distribution.
PULSECHECK targets Pulse Connect Secure appliances and functions as a server-side persistence and remote administration mechanism on those systems. In the broader intrusion set, operators used modified appliance components and scripts to maintain long-term access, bypass authentication controls, harvest credentials, and evade detection across upgrades and remediation efforts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
These attacks include using known vulnerabilities from 2019 and 2020 (CVE-2019-11510, CVE-2020-8243, and CVE-2020-8260) and a previously unknown authentication bypass vulnerability tracked as CVE-2021-22893. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"UNC2630 - SLOWPULSE, RADIALPULSE, THINBLOOD, ATRIUM, PACEMAKER, SLIGHTPULSE, and PULSECHECK"
13 distinct techniques documented for this family, organized by ATT&CK tactic.
CVE-2020-8243 (CVSS: 7.2) ... An unauthenticated threat actor could upload a customer template to perform arbitrary code execution. ... CVE-2020-8260 (CVSS: 7.2) ... an unauthenticated threat could execute arbitrary code due to a vulnerability in the admin web interface.
The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Custom malware family associated with exploitation of Pulse Secure VPN appliances during intrusions attributed to UNC2630.
Malware used by UNC2630 in Pulse Secure gateway compromises to support persistence and credential theft activities.
Perl webshell (secid_canceltoken.cgi) that executes attacker-supplied commands when a backdoor key is provided via HTTP headers; command data is RC4-encrypted and base64-encoded.
Malware that Base64-encodes encrypted data sent through command-and-control channels.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.