NebulaPulsar is a proof-of-concept, memory-resident webshell and implant framework associated with the Alien webshell platform. It uses JSP and ASP.NET server-side components as bootstrap loaders to place a resident implant in application memory, after which it receives encrypted payloads, dynamically loads Java classes or .NET assemblies in memory, and transfers execution to them. The framework manages HTTP session state and supports persistent and volatile payload-lifecycle modes. Its DarkMatter payload component provides post-exploitation functionality independently of the implant transport layer.
NebulaPulsar supports Java web environments and ASP.NET implementations, including JSP, ASPX, ASHX, and ASMX, and version 2.0 added CFML-oriented functionality through Java reflection. The framework uses encrypted communications for subsequent payload delivery and command output after bootstrap, and its .NET implementation includes an anti-forensic unload mechanism that disables a payload entry point without actually unloading its assembly. It is also used as a basis for in-memory webshell deployment techniques in compromised Java application servers, including Filter, Servlet, Valve, and Spring MVC Interceptor implants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
“A Pipeline provides the addValve() method for adding Valves to the request-processing pipeline.” | “Use reflection to locate the interceptor list within RequestMappingHandlerMapping... Inject the malicious Interceptor at the beginning (index 0) of adaptedInterceptors.” | “With a memory shell, an attacker can perform a fileless attack by injecting a new webshell into a server... while leaving no corresponding file on disk.” | “The payload creates a new Filter instance... calls standardContext.addFilterDef() and standardContext.addFilterMapBefore() to insert the malicious FilterDef into the beginning of the Filter chain.” | “A Java memory shell... use[s] reflection to dynamically load components and register malicious components into the container’s internal data structures.”
“byte[] xorDecrypted = decryptPayload(encryptedData, globalKey);”
NebulaPulsar is first injected into the target webshell and remains resident in memory.
Throughout the development process, I studied topics including... Basic anti-forensics techniques
“if (request.getMethod().equalsIgnoreCase('POST'))” and “if ('POST'.equalsIgnoreCase(request.getMethod()) && request.getHeader('X-CMD-Auth') != null).”
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A webshell used as the basis for the described Java memory-shell payloads. It can be injected into Java web-application request-processing components and accessed without creating a corresponding file on disk.
NebulaPulsar is referenced as a supported execution environment/webshell type within Alien's plugin system, used for loading and running payloads in JSP and ASPX contexts.
A webshell implant framework for Java and .NET environments that decrypts and loads an implant in memory, stores it in the current session, and then decrypts and executes follow-on payloads for arbitrary code execution.
NebulaPulsar is mentioned only as part of prior articles covering webshell generations/frameworks, without further operational detail in this reference.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.