CISA and Mandiant reported that attackers exploited Pulse Connect Secure VPN vulnerabilities—including CVE-2019-11510 and the later zero-day CVE-2021-22893—to gain initial access to government and other high-value networks, bypass authentication controls, and steal credentials. In one CISA incident response case, a federal civilian agency was compromised after the actor used valid Office 365 and domain administrator credentials, likely obtained in part through Pulse Secure exploitation, to access email and SharePoint data, enumerate Active Directory, move laterally, and stage files for likely exfiltration. The intrusion was detected through EINSTEIN, and CISA said the actor maintained command and control with scheduled tasks, SSH tunneling, reverse SOCKS proxies, mounted remote shares, PowerShell proxy tooling, and custom malware including inetinfo.exe.
Mandiant said multiple intrusions involved compromised Pulse Secure appliances that retained persistence even after upgrades, with attackers deploying web shells and malware families such as SLOWPULSE, RADIALPULSE, PULSECHECK, SLIGHTPULSE, ATRIUM, and STEADYPULSE, while THINBLOOD was used to wipe logs. The activity was linked to clusters UNC2630 and UNC2717, which targeted the U.S. defense industrial base and global government agencies, respectively, and in some cases used trojanized components to log credentials or bypass LDAP, RADIUS, and other MFA flows with a backdoor password. CISA’s alert AA21-110A, Emergency Directive 21-03, and vendor guidance urged organizations to patch affected appliances, apply mitigations, enable unauthenticated request logging, run integrity checks, and hunt for published indicators of compromise across VPN and authentication logs.

See which actors are running it and whether you're in range.
14 events from the most recent confirmed update back to the earliest known activity.
On July 21, 2021, CISA published a notice stating it had analyzed 13 malware samples associated with exploited Pulse Secure devices and released corresponding Malware Analysis Reports. The agency said the reports include threat actor tactics, techniques, procedures, and indicators of compromise for defenders.
CISA released Alert AA21-110A on April 20, 2021 concerning compromises of Pulse Connect Secure appliances and related exploitation activity.
On April 20, 2021, Mandiant published a report describing multiple recent incidents involving compromised Pulse Secure appliances, including use of webshells, authentication bypasses, and persistence across upgrades. The report said initial access involved previously disclosed 2019-2020 vulnerabilities and a newly discovered flaw, CVE-2021-22893.
The NSA issued an advisory on April 16, 2021 warning that older vulnerabilities in at least five remote access products were being actively exploited.
In April 2021, Ivanti released mitigations and the Pulse Connect Secure Integrity Tool to help customers determine whether appliances were affected by the newly disclosed compromise activity.
CISA issued Emergency Directive 21-03 requiring U.S. federal civilian agencies to take specific actions regarding Pulse Connect Secure appliances following the compromise activity.
In March 2021, Mandiant observed UNC2717 using RADIALPULSE, PULSEJUMP, and HARDPULSE at a European organization.
Mandiant assessed that UNC2717 targeted global government agencies between October 2020 and March 2021 using HARDPULSE, QUIETPULSE, and PULSEJUMP.
Mandiant assessed that UNC2630 targeted U.S. defense industrial base companies from as early as August 2020 through March 2021 using malware including SLOWPULSE, RADIALPULSE, THINBLOOD, ATRIUM, PACEMAKER, SLIGHTPULSE, and PULSECHECK.
In August 2020, two underground credential lists containing directories, files, plaintext usernames and passwords, and IP addresses for more than 1,200 Pulse Secure VPN servers were shared. KELA later identified five ransomware victims whose Pulse Secure credentials appeared in those lists, linking the exposure to follow-on ransomware intrusions.
On September 11, 2019, Volexity warned that vulnerable Pulse Secure SSL VPN devices were being exploited in the wild, with credentials used on affected devices since early August 2019 potentially compromised. The report also described theft of cleartext credential databases and hijacking of active VPN sessions using valid DSID cookies, and provided detection guidance for defenders.
Pulse Secure released patches in April 2019 for critical vulnerabilities including CVE-2019-11510, a flaw later assessed as likely used to obtain credentials in a federal agency compromise.
Pulse Secure released an update on May 3, 2021 addressing multiple vulnerabilities affecting Pulse Connect Secure appliances, including issues tied to the April 2021 disclosures.
CISA published analysis of an incident response engagement involving a compromised federal civilian agency network detected through EINSTEIN. The actor used valid Office 365 and domain administrator credentials, likely obtained in part through exploitation of CVE-2019-11510 on an unpatched Pulse Secure VPN server, then established persistence, moved laterally, and likely exfiltrated data.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 34 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
14 references tracked. Mallory keeps watching after this page renders.
blog.pulsesecure.net
Open sourcekb.pulsesecure.net
Open sourcecve.mitre.org
Open sourcegithub.com
Open sourceus-cert.cisa.gov
Open sourcezdnet.com
Open sourcevolexity.com
Open sourcecyber.dhs.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.