RAPIDPULSE is a web shell and modification to a legitimate Pulse Secure file, designed specifically to infect Pulse Secure VPN appliances. It enables arbitrary file read on targeted web servers and can function as an encrypted file downloader for attackers, using RC4 and Base64. Mandiant and FLARE identified it in investigations of compromised Pulse Secure VPN devices affecting organizations in the defense, government, high tech, transportation, and financial sectors in the U.S. and Europe. The activity was attributed by Mandiant to suspected Chinese espionage operators, including clusters UNC2630 and UNC2717, and assessed as supporting Chinese government strategic priorities. RAPIDPULSE was part of a broader set of Pulse-focused malware families used to maintain footholds on compromised appliances following exploitation of Pulse Secure vulnerabilities, including CVE-2021-22893 and previously disclosed 2019 and 2020 issues.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"RAPIDPULSE is a webshell capable of arbitrary file read... RAPIDPULSE can serve as an encrypted file downloader for the attacker."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"RAPIDPULSE is a webshell capable of arbitrary file read... RAPIDPULSE can serve as an encrypted file downloader for the attacker."
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pulse Secure appliance webshell implemented by modifying a legitimate Pulse Secure file; enables arbitrary file read and encrypted file download via RC4 decryption/encryption and base64 encoding over HTTP parameters.
Web shell focused on arbitrary file read for collection/exfiltration from compromised web servers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.