PuzzleMaker is a threat actor identified following highly targeted attacks against multiple companies on April 14–15, 2021. Its operations combined exploitation through Google Chrome with two Windows kernel zero-day vulnerabilities to escape the browser sandbox and obtain SYSTEM privileges. Its country of origin, organizational affiliation, and motivation have not been established. The Windows exploit chain combined CVE-2021-31955, a SuperFetch-related information disclosure vulnerability exposing kernel process addresses, with CVE-2021-31956, an NTFS heap-based buffer overflow. The actor used Windows Notification Facility structures to establish arbitrary memory read and write capabilities, then abused the PreviousMode technique to inject and execute a malware module in the system process. The exploits supported multiple Windows 10 builds. Both Windows vulnerabilities were patched in June 2021; the exact Chrome vulnerability used was not conclusively identified. PuzzleMaker's post-exploitation toolchain comprised a stager, dropper, service component, and remote shell. The stager reported successful exploitation and retrieved an encrypted dropper. The dropper installed a service and remote shell masquerading as legitimate Windows components. The remote shell supported file uploads and downloads, process creation, sleep, and self-deletion, providing persistent remote control and file-transfer capabilities. No strong malware-family links or attribution to an established group were identified. Although its use of PreviousMode overlapped with the CHAINSHOT framework, this technique alone does not establish an operational relationship.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
An example of this is CVE-2021-31955 (SuperfetchPrivSourceQuery system information class) that was used in the PuzzleMaker APT Google Chrome attack chain.
Magnitude using CVE-2021-21224 and CVE-2021-31956 ... This is an exploit for CVE-2021-31956, a paged pool buffer overflow in the Windows kernel ... The first one contains an exploit for CVE-2021-31956. This one gets executed first and its goal is to steal the SYSTEM token to elevate the privileges of the current process.
This newly published exploit used a vulnerability from issue 1195777, worked on the newly released Chrome 90.0.4430.72, and was fixed as CVE-2021-21224 only a few days later, on April 20, 2021. We suspect the attackers were also able to use this JavaScript file with regression test to develop the exploit (or acquire it from someone else) and were probably using CVE-2021-21224 in their attacks.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a threat actor discussed in connection with CHAINSHOT based on a rare technique (association described as non-exclusive).
Mentioned as a historical example of an actor using a Windows kernel information-disclosure vulnerability in a Google Chrome attack chain. The content does not attribute the CVE-2022-24521 exploitation or the CLFS ransomware attacks to PuzzleMaker.
Referenced as the earlier threat activity that used CVE-2021-31956 as a zero-day before Magnitude later weaponized the same vulnerability.
Conducted highly targeted attacks against multiple companies using a chain of Google Chrome and Microsoft Windows zero-day exploits, followed by a multi-stage malware chain including a stager, dropper, service, and remote shell.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.