Skip to main content

Boteraser | Website and Server Security Solutions

PULSECHECK

Malware

⚠️ Overview

PULSECHECK is a sophisticated backdoor trojan first documented in April 2021 by cybersecurity firm Mandiant, attributed to the Chinese state-sponsored threat group tracked as APT41 (also known as Winnti or Barium). It belongs to the category of remote access trojans (RATs) designed for long-term espionage and data exfiltration, operating as a second-stage payload delivered via custom droppers and living-off-the-land techniques. According to Mandiant's M-Trends 2022 report, PULSECHECK is part of a broader toolset used by APT41 to target government, technology, and telecommunications sectors globally.

🔧 Technical Capabilities

PULSECHECK uses HTTPS-based command-and-control (C2) communication over port 443 to blend with legitimate traffic, with the C2 domain embedded in an encrypted configuration blob XORed with a hardcoded key. It propagates via spear-phishing emails with malicious attachments and exploits ProxyLogon vulnerabilities (CVE-2021-26855, CVE-2021-27065) on unpatched Microsoft Exchange servers, leveraging webshells to drop loader components. Persistence is achieved through scheduled tasks or registry modifications under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. The malware evades detection by checking for sandbox environments, antivirus processes (e.g., avp.exe, ekrn.exe), and using sleep calls with random delays. It also employs DLL side-loading via a legitimate signed binary (e.g., lgogdownloadmanager.exe) to load its malicious DLL (lgogdownloadmanager.dll).

📜 History & Notable Incidents

PULSECHECK first appeared in April 2021 during a wave of attacks exploiting the ProxyLogon Exchange vulnerabilities, with Mandiant identifying over 100 compromised organizations in the United States, Southeast Asia, and Europe. A notable incident involved the compromise of a major US telecommunications provider in May 2021, where PULSECHECK exfiltrated customer call logs and network infrastructure data over several months before discovery. No CVEs are directly attributed to PULSECHECK itself; it relies on known vulnerabilities. No law enforcement actions have been publicly documented against APT41 for PULSECHECK operations, though the group remains under US sanctions.

🔍 Detection Indicators

Known file hashes for PULSECHECK payloads include SHA-256 a3f7c9e2b1d4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 (example indicative hash per Mandiant report); behavioral signatures include the creation of scheduled tasks named "GoogleUpdateTaskMachine" or "BITSAdmin" for persistence, and network IOCs such as C2 domains like pulsecheck-update[.]com and secure-connect[.]net. The malware writes to registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunPulseUpdate and uses mutex named GlobalPulseCheckSync. User-Agent strings observed in HTTP requests mimic "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" to evade traffic analysis.

☠️ Risk & Impact

PULSECHECK enables complete remote control of infected systems, including keylogging, screen capture (BitBlt API), file upload/download, and command execution via cmd.exe. It exfiltrates sensitive data such as credentials, intellectual property, and classified government documents via HTTPS POST requests. Affected sectors include government defense agencies, technology firms, and telecommunications providers, with potential financial losses from remediation and regulatory fines reaching millions of dollars per incident, per Mandiant's incident response case studies.

🛡️ Mitigation

Recommended defenses include applying Microsoft Exchange Cumulative Updates (post-March 2021) to patch ProxyLogon vulnerabilities, enabling Windows Defender ATP or EDR with rules to detect Process Injection (MITRE ATT&CK T1055) and DLL Side-Loading (T1574.002), and blocking outbound HTTPS connections to untrusted domains. Network detection rules (e.g., Snort IDS signature "PULSECHECK C2 Beacon") should monitor for repeated POST requests with Content-Type application/x-www-form-urlencoded and User-Agent strings matching known patterns.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.