ATRIUM is a webshell used in intrusions involving Pulse Secure Connect Secure VPN appliances. It is associated with exploitation activity tracked under UNC2630 and has been linked by multiple investigations to China-nexus espionage operations, including activity overlapping with APT5. ATRIUM was deployed against organizations including U.S. Defense Industrial Base entities during campaigns active from at least 2020 into 2021.
ATRIUM is implemented by modifying a legitimate Pulse Secure component to provide attacker-controlled command execution. The implant executes attacker-supplied input received through an HTTP query parameter, enabling post-compromise remote administration on the appliance. It has been used as a persistence mechanism on compromised VPN gateways, including through modification of legitimate upgrade-related scripts so the webshell can survive software upgrades and reappear after remediation attempts focused only on active filesystems.
Operationally, ATRIUM formed part of a broader Pulse Secure malware ecosystem that included credential theft, authentication bypass, log tampering, and upgrade-persistence tooling. In observed campaigns, operators used compromised appliances as footholds for long-term access, credential harvesting, lateral movement into internal environments, and follow-on espionage activity. Targeting spanned government, defense, financial, and other sectors in the U.S. and Europe. ATRIUM is notable as one of several Pulse-specific webshells used to maintain covert access on network edge infrastructure while blending into legitimate appliance components.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
On April 20, 2021, Mandiant reported that previously known PCS vulnerabilities (CVE-2019-11510, CVE-2020-8243, CVE-2020-8260) and a zero-day (CVE-2021-22893) were exploited as early as August 2020, and some activity was still observed through March 2021. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
These attacks include using known vulnerabilities from 2019 and 2020 (CVE-2019-11510, CVE-2020-8243, and CVE-2020-8260) and a previously unknown authentication bypass vulnerability tracked as CVE-2021-22893. | Mandiant reported that twelve (12) malware families were used against organizations that were victim of the PCS attacks, including: ATRIUM, HARPULSE, LOCKPICK, PACEMAKER, PULSECHECK, PULSEJUMP, QUIETPULSE, RADIALPULSE, SLIGHTPULSE, SLOWPULSE, STEADYPULSE, and THINBLOOD.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
APT5 has modified legitimate binaries and scripts for Pulse Secure VPNs including the legitimate DSUpgrade.pm file to install the ATRIUM webshell for persistence.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
CVE-2020-8243 (CVSS: 7.2) ... An unauthenticated threat actor could upload a customer template to perform arbitrary code execution. ... CVE-2020-8260 (CVSS: 7.2) ... an unauthenticated threat could execute arbitrary code due to a vulnerability in the admin web interface.
APT5 has modified legitimate binaries and scripts for Pulse Secure VPNs including the legitimate DSUpgrade.pm file to install the ATRIUM webshell for persistence.
"They modified scripts on the Pulse Secure system which enabled the malware to survive software updates and factory resets."
Multiple modified Pulse Secure CGI/Perl scripts act as webshells (e.g., licenseserverproto.cgi, secid_canceltoken.cgi, compcheckresult.cgi) that parse HTTP parameters/headers and execute attacker-supplied commands, returning output in HTTP responses (sometimes masquerading as GIF/text/html).
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Web shell used for persistence on compromised Pulse Secure VPN appliances.
Pulse Secure appliance webshell used for persistent access; also referenced as being re-installed via upgrade-process persistence mechanisms (e.g., DSUpgrade.pm modification) and found near other tooling (e.g., CLEANPULSE).
Custom malware family associated with exploitation of Pulse Secure VPN appliances during intrusions attributed to UNC2630.
Malware used by UNC2630 in PCS gateway compromises to support persistence and credential harvesting operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.