PuzzleMaker is a threat actor name assigned to a previously unidentified cluster responsible for a wave of highly targeted attacks observed in April 2021. The activity used a Chrome-based exploit chain combined with two Windows kernel zero-days, CVE-2021-31955 and CVE-2021-31956, to escape the browser sandbox and obtain SYSTEM privileges on Windows 10 systems. Researchers assessed the Chrome remote code execution component was likely related to CVE-2021-21224. The actor’s operations were characterized by precise exploit delivery against multiple companies rather than broad watering-hole activity. The intrusion chain included a stager, dropper, service component, and remote shell payload. After successful exploitation, the stager notified operators and retrieved the next stage. The malware provided remote shell functionality and supported actions including file upload, file download, process creation, sleep control, and self-deletion. The actor used the Windows kernel PreviousMode technique during post-exploitation to inject a malware module into the system process and execute it. PuzzleMaker demonstrated advanced exploitation capability, including use of an information disclosure vulnerability to recover kernel addresses and a heap-based buffer overflow in the Windows kernel to achieve arbitrary kernel memory access and privilege escalation. The exploit abused Windows Notification Facility structures to build read/write primitives and then leveraged token theft to obtain elevated execution. The actor has been discussed in connection with CHAINSHOT because of overlap in a rare exploitation technique, but no strong attribution to a known group is established on that basis alone. PuzzleMaker is best understood as a highly capable exploit-using intrusion actor associated with targeted post-exploitation access and remote control, with no high-confidence public linkage to a specific malware family beyond the bespoke toolchain used in these attacks and no high-confidence public attribution to a nation state or country of origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Kaspersky reported that PuzzleMaker used a separate information disclosure vulnerability, CVE-2021-31955, to leak the _EPROCESS base address.
Magnitude using CVE-2021-21224 and CVE-2021-31956 ... This is an exploit for CVE-2021-31956, a paged pool buffer overflow in the Windows kernel ... The first one contains an exploit for CVE-2021-31956. This one gets executed first and its goal is to steal the SYSTEM token to elevate the privileges of the current process.
This newly published exploit used a vulnerability from issue 1195777, worked on the newly released Chrome 90.0.4430.72, and was fixed as CVE-2021-21224 only a few days later, on April 20, 2021. We suspect the attackers were also able to use this JavaScript file with regression test to develop the exploit (or acquire it from someone else) and were probably using CVE-2021-21224 in their attacks.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a threat actor discussed in connection with CHAINSHOT based on a rare technique (association described as non-exclusive).
Referenced as the earlier threat activity that used CVE-2021-31956 as a zero-day before Magnitude later weaponized the same vulnerability.
Conducted highly targeted attacks against multiple companies using a chain of Google Chrome and Microsoft Windows zero-day exploits, followed by a multi-stage malware chain including a stager, dropper, service, and remote shell.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.