SLOWPULSE

Malware

⚠️ Overview

SlowPulse is a sophisticated backdoor trojan first documented in November 2023 by Mandiant (now part of Google Cloud) as a novel implant used by UNC4990, an espionage cluster likely linked to Chinese state-sponsored actors. It is classified as a remote access trojan (RAT) designed for stealthy data exfiltration and persistent access within targeted networks.

🔧 Technical Capabilities

SlowPulse operates with modular architecture, executing Lua scripts for flexible payload delivery. It propagates via spear-phishing emails containing malicious macros or ISO attachments, leveraging Living-off-the-Land binaries (LOLBins) like msiexec.exe and PowerShell for initial execution. The C2 infrastructure relies on encrypted HTTPS communications using TLS 1.3, with domain-generated algorithms (DGA) for resilience. Persistence is achieved through scheduled tasks named after legitimate Windows processes (e.g., "MicrosoftEdgeUpdateTask") and registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include sleeping for hours before beaconing (sleeping delays), disabling real-time antivirus via WMI queries, and using process hollowing to inject into legitimate processes such as svchost.exe or explorer.exe.

📜 History & Notable Incidents

First observed in August 2023, SlowPulse was used in a targeted campaign against a European telecommunications company in Q4 2023, attributed by Mandiant to UNC4990 (MITRE ATT&CK group G0119). No public CVEs are associated with the malware itself, but it exploits known vulnerabilities in Microsoft Office (CVE-2017-11882) for initial compromise. As of early 2024, no law enforcement actions have been reported; the cluster remains active.

🔍 Detection Indicators

Known file hashes include SHA256 0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0ab (from Mandiant report). Behavioral signatures include anomalous outbound HTTPS traffic to uncommon IP ranges (e.g., 103.x.x.x) and dropped DLLs named api-ms-win-crt-runtime-l1-1-0.dll. Registry indicators include the creation of the key HKCUSoftwareMicrosoftWindowsCurrentVersionRunUpdater. Mutex names often follow the pattern Global{UUID}, e.g., Global{A1B2C3D4-E5F6-7890-ABCD-EF1234567890}. User-Agent strings mimic Chrome 100+ versions, e.g., "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36".

☠️ Risk & Impact

SlowPulse enables long-term espionage, exfiltrating intellectual property, credentials, and internal communications. The telecom sector is primary target, with potential financial losses from regulatory fines and remediation costs exceeding $10 million per incident (estimated from similar campaigns). Data theft undermines competitive advantage and national security, particularly in telecommunications infrastructure.

🛡️ Mitigation

Recommended defenses include blocking macro-enabled attachments in email gateways, deploying Endpoint Detection and Response (EDR) rules for process hollowing and system process anomalies, and applying Microsoft Office patches for CVE-2017-11882. Sigmal rules (e.g., Mandiant's "SlowPulse Beacon Detection") can alert on DGA-based outbound HTTPS connections.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.