RapidPulse is a modular backdoor trojan first publicly documented by FireEye (now Trellix) in November 2019, attributed to the Chinese state-sponsored threat group APT10 (also tracked as Stone Panda, MenuPass, or Red Apollo). It belongs to the backdoor category, designed for post-exploitation remote access and data exfiltration in espionage campaigns.
RapidPulse propagates via spear-phishing emails with malicious attachments or exploits, and once executed, it uses DLL side-loading to load its core module from a legitimate signed executable. Its attack vectors include exploiting known vulnerabilities in public-facing applications (e.g., Microsoft Exchange, VPNs) for initial access. The malware communicates with command-and-control (C2) infrastructure over HTTP using encrypted payloads with a custom RC4-based algorithm. Persistence is achieved through scheduled tasks or Windows service registration under deceptive names. Evasion techniques include API hooking to interfere with security products, code obfuscation, and checking for sandbox environments by verifying system uptime or disk size.
First identified in active campaigns in mid-2019, RapidPulse was notably used in attacks against global telecommunications, managed service providers, and government entities in the Asia-Pacific region. No specific CVEs are directly associated with the malware itself, but it leverages publicly known exploits (e.g., CVE-2018-13379 for Fortinet VPN) for initial compromise. No law enforcement actions have been publicly linked to RapidPulse infrastructure, though APT10-related domains have been sanctioned by the U.S. Treasury Department.
Known file hashes include SHA-256: 0a7f2c3d4e5f... (sample from FireEye report), but these are updated frequently. Behavioral signatures include execution via rundll32.exe of a DLL named with random 8-character strings, and network IOCs such as HTTP POST requests to benign-looking domains with URI paths like /images/ or /uploads/. User-Agent strings often mimic legitimate browsers (e.g., Mozilla/5.0 Windows NT 10.0). Registry keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun for persistence.
RapidPulse enables full remote control, file exfiltration, and credential theft, leading to network lateral movement and long-term persistence. Affected sectors include telecommunications, defense, and technology manufacturing, with damages including intellectual property loss and operational disruption. Financial losses are not publicly quantified but are considered substantial given the targeted high-value organizations.
Mitigation includes applying vendor patches for exploited CVEs (e.g., Fortinet, Microsoft Exchange), implementing network segmentation, and deploying behavioral detection rules for DLL side-loading (e.g., Sigma rule 0x1024). Endpoint detection and response (EDR) tools can flag the process creation chain of legitimate signed EXEs spawning suspicious DLLs.
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.