SLOWPULSE — Malware Profile
SLOWPULSE is a malware that was used by APT5 as early as 2020 including against U.S. Defense Industrial Base (DIB) companies. SLOWPULSE has several variants and can modify legitimate Pulse Secure VPN files in order to log credentials and bypass single and two-factor authentication flows.
MITRE ATT&CK techniques (6)
- T1027 Obfuscated Files or Information
- T1074.001 Local Data Staging
- T1111 Multi-Factor Authentication Interception
- T1554 Compromise Host Software Binary
- T1556.004 Network Device Authentication
- T1556.006 Multi-Factor Authentication