puzzlemaker

First seen
2021-05-12 00:00:00
Malware type
dropper, rat
Family
Malware family
Profile updated
2026-07-07 14:52:12

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

The dropper module is used to install two executables that pretend to be legitimate files belonging to Microsoft Windows OS. One of these files (%SYSTEM%\WmiPrvMon.exe) is registered as a service and is used as a launcher for the second executable. This second executable (%SYSTEM%\wmimon.dll) has the functionality of a remote shell and can be considered the main payload of the attack.

Detection coverage

  • 3 YARA rules

Detection rules

  • ARKBIRD_SOLG_APT_Puzzlemaker_Launcher_Jun_2021_1 (yara-rule)
  • ARKBIRD_SOLG_APT_Puzzlemaker_Implant_Jun_2021_1 (yara-rule)
  • MALPEDIA_Win_Puzzlemaker_Auto (yara-rule)

Reports & references

  • Kaspersky — 102771 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Puzzlemaker (report)

External references