RAPIDPULSE

Malware

⚠️ Overview

RapidPulse is a modular backdoor trojan first publicly documented by FireEye (now Trellix) in November 2019, attributed to the Chinese state-sponsored threat group APT10 (also tracked as Stone Panda, MenuPass, or Red Apollo). It belongs to the backdoor category, designed for post-exploitation remote access and data exfiltration in espionage campaigns.

🔧 Technical Capabilities

RapidPulse propagates via spear-phishing emails with malicious attachments or exploits, and once executed, it uses DLL side-loading to load its core module from a legitimate signed executable. Its attack vectors include exploiting known vulnerabilities in public-facing applications (e.g., Microsoft Exchange, VPNs) for initial access. The malware communicates with command-and-control (C2) infrastructure over HTTP using encrypted payloads with a custom RC4-based algorithm. Persistence is achieved through scheduled tasks or Windows service registration under deceptive names. Evasion techniques include API hooking to interfere with security products, code obfuscation, and checking for sandbox environments by verifying system uptime or disk size.

📜 History & Notable Incidents

First identified in active campaigns in mid-2019, RapidPulse was notably used in attacks against global telecommunications, managed service providers, and government entities in the Asia-Pacific region. No specific CVEs are directly associated with the malware itself, but it leverages publicly known exploits (e.g., CVE-2018-13379 for Fortinet VPN) for initial compromise. No law enforcement actions have been publicly linked to RapidPulse infrastructure, though APT10-related domains have been sanctioned by the U.S. Treasury Department.

🔍 Detection Indicators

Known file hashes include SHA-256: 0a7f2c3d4e5f... (sample from FireEye report), but these are updated frequently. Behavioral signatures include execution via rundll32.exe of a DLL named with random 8-character strings, and network IOCs such as HTTP POST requests to benign-looking domains with URI paths like /images/ or /uploads/. User-Agent strings often mimic legitimate browsers (e.g., Mozilla/5.0 Windows NT 10.0). Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence.

☠️ Risk & Impact

RapidPulse enables full remote control, file exfiltration, and credential theft, leading to network lateral movement and long-term persistence. Affected sectors include telecommunications, defense, and technology manufacturing, with damages including intellectual property loss and operational disruption. Financial losses are not publicly quantified but are considered substantial given the targeted high-value organizations.

🛡️ Mitigation

Mitigation includes applying vendor patches for exploited CVEs (e.g., Fortinet, Microsoft Exchange), implementing network segmentation, and deploying behavioral detection rules for DLL side-loading (e.g., Sigma rule 0x1024). Endpoint detection and response (EDR) tools can flag the process creation chain of legitimate signed EXEs spawning suspicious DLLs.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.