S1113: RAPIDPULSE
MITRE ATT&CK S1113: RAPIDPULSE Malware details for Network Devices, Linux, with detection guidance, relationships and mapped CVEs.
Security context for executives and security teams
RAPIDPULSE matters because it represents a web shell hidden as a modification to a legitimate Pulse Secure file on network device/Linux infrastructure. For leaders, the key issue is not just malware cleanup; it is whether internet-facing access infrastructure can be trusted, rebuilt, and monitored well enough after suspected compromise.
Executive priority
Prioritize RAPIDPULSE-related readiness where Pulse Secure or similar network access devices are business-critical. The ATT&CK context ties this malware to APT5 and to web shell persistence, local data collection, and obfuscation behaviors, so incident decisions should consider credential exposure, device integrity, and whether network edge appliances are included in logging, backup, rebuild, and audit evidence programs.
Technical view
Validate whether SOC and IR teams can inspect Pulse Secure-related file integrity on network devices/Linux systems, compare legitimate files against trusted baselines, and investigate anomalous web-access or administrative activity. Because ATT&CK provides no official detection text for RAPIDPULSE, detection engineering should be relationship-driven: T1505.003 Web Shell for persistence, T1005 Data from Local System for local collection, and T1027.013/T1140 for encoded or decoded artifacts that may obscure content.
Likely telemetry
- Network device and Linux filesystem integrity evidence for web-accessible and vendor application files
- Web server or appliance access logs showing unusual requests to legitimate-looking files
- Administrative login, configuration change, and device management logs
- Process execution or script invocation telemetry where available on the appliance or underlying Linux host
- Configuration backups, known-good images, and file hashes for comparison
Detection direction
- Confirm that edge network devices are in scope for monitoring; many SOC programs have weaker telemetry on appliances than on endpoints.
- Tune for unauthorized modification of legitimate Pulse Secure files rather than only newly created suspicious filenames.
- Correlate file changes with web requests, administrative activity, and any local data access indicators consistent with T1005.
- Account for obfuscation: encoded file content or decoded runtime artifacts may reduce the value of simple string matching.
- Use APT5 relationship context for threat intelligence prioritization, especially for organizations in sectors named in the related group description, without assuming local compromise.
Mitigation priorities
- Maintain trusted baselines and recoverable backups for network access appliances and their underlying file systems.
- Include VPN/network devices in patch, configuration management, logging, and incident response playbooks.
- Restrict and monitor administrative access to appliance management interfaces.
- When compromise is suspected, prioritize integrity validation and rebuild from trusted media over file-by-file cleanup alone.
- Preserve logs and file evidence before remediation to support incident scoping and compliance reporting.
Additional notes and limits
The official object identifies RAPIDPULSE as a web shell modification to a legitimate Pulse Secure file and states it has been used by APT5 since at least 2021. Relationship context provides the strongest defensive framing: persistence through Web Shell, possible local data collection, and obfuscation/deobfuscation behaviors.
ATT&CK provides no official detection guidance, no aliases, and no object-level tactics for RAPIDPULSE. Local applicability depends on whether the environment uses relevant Pulse Secure/network device infrastructure and whether appliance-level telemetry is retained and accessible.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
RAPIDPULSE
No official description is available in the imported ATT&CK source object.
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
