puzzlemaker
- First seen
- 2021-05-12 00:00:00
- Malware type
- dropper, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 14:52:12
Targeted industries: government-and-public-sector technology-and-telecommunications
Context
The dropper module is used to install two executables that pretend to be legitimate files belonging to Microsoft Windows OS. One of these files (%SYSTEM%\WmiPrvMon.exe) is registered as a service and is used as a launcher for the second executable. This second executable (%SYSTEM%\wmimon.dll) has the functionality of a remote shell and can be considered the main payload of the attack.
Detection coverage
- 3 YARA rules
Detection rules
- ARKBIRD_SOLG_APT_Puzzlemaker_Launcher_Jun_2021_1 (yara-rule)
- ARKBIRD_SOLG_APT_Puzzlemaker_Implant_Jun_2021_1 (yara-rule)
- MALPEDIA_Win_Puzzlemaker_Auto (yara-rule)
Reports & references
- Kaspersky — 102771 (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Puzzlemaker (report)