Cyber Threat Report: 'Suspected APT Actors Leverage Authentication Bypass Techniques and Pulse Secure Zero-Day'

Report Author Mandiant
Publication Date 2021-04-20
Original Reporting Source
Attributed to Nation China
Related Intrusion Sets UNC2717 , UNC2630
Identified CVEs CVE-2021-22893
Victim Sectors National Government, Financial Services, Defense

Reporting from Mandiant which discusses the exploitation of Pulse Secure VPN devices in 2021 and 12 malware families associated with the campaign. The report identifies activities associated with at lease two distinct intrusion sets: UNC2717 and UNC2630.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques