BLOODMINE is a utility malware/tool designed for Pulse Secure VPN appliances. It parses Pulse Secure Connect log files and extracts information related to logins, message IDs, and web requests, copying relevant data to another file. Reporting states it was used by APT5 and also identified by Mandiant in investigations of suspected Chinese espionage activity involving Pulse Secure compromises. Mandiant/FLARE described BLOODMINE as one of multiple malware families exclusively designed to infect Pulse Secure VPN appliances. Observed use includes discovering files with .css, .jpg, .png, .gif, .ico, .js, and .jsp extensions in Pulse Secure Connect logs and collecting data on web requests from those logs. The broader intrusion activity associated with its use involved exploitation of Pulse Secure vulnerabilities, persistence via web shells and modified legitimate Pulse components, credential theft, lateral movement, and targeting of sectors including defense, government, high tech, transportation, and financial organizations in the U.S. and Europe. High-confidence behavioral detail specific to BLOODMINE is limited to Pulse Secure log parsing and extraction of login- and web-request-related data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"BLOODMINE is a utility for parsing Pulse Secure Connect log files. It extracts information related to logins, Message IDs and Web Requests and copies the relevant data to another file."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"BLOODMINE is a utility for parsing Pulse Secure Connect log files. It extracts information related to logins, Message IDs and Web Requests and copies the relevant data to another file."
3 distinct techniques documented for this family, organized by ATT&CK tactic.
APT5 has used the BLOODMINE utility to collect data on web requests from Pulse Secure Connect logs.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Utility used to parse Pulse Secure Connect logs, discover files, and collect data on web requests.
Utility designed for Pulse Secure VPN appliances that parses Pulse Secure Connect logs to extract login and web request metadata and writes the extracted data to an output file.
Utility used to collect and parse Pulse Secure Connect logs (web request data) for reconnaissance/collection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.