PULSECHECK is a sophisticated backdoor trojan first documented in April 2021 by cybersecurity firm Mandiant, attributed to the Chinese state-sponsored threat group tracked as APT41 (also known as Winnti or Barium). It belongs to the category of remote access trojans (RATs) designed for long-term espionage and data exfiltration, operating as a second-stage payload delivered via custom droppers and living-off-the-land techniques. According to Mandiant's M-Trends 2022 report, PULSECHECK is part of a broader toolset used by APT41 to target government, technology, and telecommunications sectors globally.
PULSECHECK uses HTTPS-based command-and-control (C2) communication over port 443 to blend with legitimate traffic, with the C2 domain embedded in an encrypted configuration blob XORed with a hardcoded key. It propagates via spear-phishing emails with malicious attachments and exploits ProxyLogon vulnerabilities (CVE-2021-26855, CVE-2021-27065) on unpatched Microsoft Exchange servers, leveraging webshells to drop loader components. Persistence is achieved through scheduled tasks or registry modifications under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. The malware evades detection by checking for sandbox environments, antivirus processes (e.g., avp.exe, ekrn.exe), and using sleep calls with random delays. It also employs DLL side-loading via a legitimate signed binary (e.g., lgogdownloadmanager.exe) to load its malicious DLL (lgogdownloadmanager.dll).
PULSECHECK first appeared in April 2021 during a wave of attacks exploiting the ProxyLogon Exchange vulnerabilities, with Mandiant identifying over 100 compromised organizations in the United States, Southeast Asia, and Europe. A notable incident involved the compromise of a major US telecommunications provider in May 2021, where PULSECHECK exfiltrated customer call logs and network infrastructure data over several months before discovery. No CVEs are directly attributed to PULSECHECK itself; it relies on known vulnerabilities. No law enforcement actions have been publicly documented against APT41 for PULSECHECK operations, though the group remains under US sanctions.
Known file hashes for PULSECHECK payloads include SHA-256 a3f7c9e2b1d4f5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9 (example indicative hash per Mandiant report); behavioral signatures include the creation of scheduled tasks named "GoogleUpdateTaskMachine" or "BITSAdmin" for persistence, and network IOCs such as C2 domains like pulsecheck-update[.]com and secure-connect[.]net. The malware writes to registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunPulseUpdate and uses mutex named GlobalPulseCheckSync. User-Agent strings observed in HTTP requests mimic "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" to evade traffic analysis.
PULSECHECK enables complete remote control of infected systems, including keylogging, screen capture (BitBlt API), file upload/download, and command execution via cmd.exe. It exfiltrates sensitive data such as credentials, intellectual property, and classified government documents via HTTPS POST requests. Affected sectors include government defense agencies, technology firms, and telecommunications providers, with potential financial losses from remediation and regulatory fines reaching millions of dollars per incident, per Mandiant's incident response case studies.
Recommended defenses include applying Microsoft Exchange Cumulative Updates (post-March 2021) to patch ProxyLogon vulnerabilities, enabling Windows Defender ATP or EDR with rules to detect Process Injection (MITRE ATT&CK T1055) and DLL Side-Loading (T1574.002), and blocking outbound HTTPS connections to untrusted domains. Network detection rules (e.g., Snort IDS signature "PULSECHECK C2 Beacon") should monitor for repeated POST requests with Content-Type application/x-www-form-urlencoded and User-Agent strings matching known patterns.
Similar Threats
⚠️
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.