PULSEPACK is a modular .NET backdoor/implant associated with the China-linked threat actor Earth Lamia. It was first identified in Earth Lamia intrusions in August 2024 and has been observed deployed via DLL side-loading, including sideloading into trusted executables. The malware establishes communication with a remote command-and-control server and retrieves plugins on demand, with the core executable primarily handling C2 while plugins extend functionality. Reported capabilities include dynamic loading of encrypted Base64 plugins and encrypted data transmission using AES. Trend Micro observed an updated version in March 2025 that changed C2 communications from TCP to WebSocket, indicating ongoing active development. PULSEPACK has been used in campaigns targeting organizations in Brazil, India, and Southeast Asia, including sectors such as logistics, online retail, IT, universities, government, and previously financial services. It has been deployed alongside other backdoors and tooling used by Earth Lamia, including Vshell and Brute Ratel. High-confidence behavioral indicators from the content include DLL side-loading, modular plugin retrieval from C2, WebSocket-based C2 in newer versions, and AES-encrypted communications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
PULSEPACK is a .NET backdoor used to establish remote communication and load additional plugins for post-exploitation activities.
PULSEPACK is a modular .NET-based backdoor used by the China-linked threat actor Earth Lamia. It is deployed via DLL side-loading and communicates with a remote server to retrieve plugins for various malicious functions. The malware is under active development, with recent updates changing its C2 communication method from TCP to WebSocket.
PULSEPACK is a modular .NET-based backdoor used by Earth Lamia. It features WebSocket-based command and control, dynamic loading of encrypted plugins, and AES-encrypted data transmission, indicating it is under active development for stealthy and flexible operations.
PULSEPACK is a modular .NET backdoor developed by Earth Lamia. It is designed to provide remote command-and-control (C&C) access, with a minimal core that loads additional malicious functionality as plugins from the C&C server. It collects system information, supports plugin-based extensibility, and uses AES encryption for communication. The backdoor has evolved to use WebSocket-based C&C and improved modularity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.