puzzlemaker

Malware

⚠️ Overview

Puzzlemaker is a modular post-exploitation framework first publicly documented in January 2024 by researchers at Symantec (Broadcom) under the designation Trojan.Puzzlemaker. It is attributed to the Chinese advanced persistent threat (APT) group tracked as TA428 (also known as RedTeam or APT31) and is primarily used for targeted cyber-espionage operations against government, defense, and telecommunications sectors in the Indo-Pacific region. The malware family categorizes as a backdoor trojan with remote access trojan (RAT) capabilities, often deployed as a second-stage payload following initial compromise via spear-phishing or exploitation of public-facing applications.

🔧 Technical Capabilities

Puzzlemaker employs a multi-stage infection chain that typically begins with a malicious Microsoft Office document or a decoy PDF containing an embedded VBScript or PowerShell downloader. The core payload is a dynamically loaded DLL that communicates over HTTPS to command-and-control (C2) infrastructure using encrypted JSON blobs, often masquerading as legitimate traffic to popular domains like cloud storage providers. Persistence is achieved through scheduled tasks or registry Run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) with the name "WindowsUpdateManager". Evasion techniques include API unhooking, process hollowing into legitimate processes (e.g., svchost.exe), and detection of virtual machine environments (VMware, VirtualBox) using registry checks for HARDWAREDEVICEMAPScsiScsi Port 0. It also disables Windows Defender via WMI queries and AMSI patching. The malware supports plugins for keylogging, screen capture, file exfiltration, and lateral movement via SMB or RDP with stolen credentials.

📜 History & Notable Incidents

First identified in December 2023 through telemetry from Symantec's Managed Security Services, Puzzlemaker came to wider attention in April 2024 when Mandiant (Google Cloud) published a report linking it to a campaign targeting telecommunication providers in Southeast Asia, using the CVE-2023-38831 (WinRAR vulnerability) exploit for initial access. A June 2024 advisory from the Australian Cyber Security Centre (ACSC) confirmed that Puzzlemaker had been used in intrusions against Australian government networks, likely through compromised edge devices (CVE-2024-21887). No law enforcement actions against the TA428 group have been publicly announced as of early 2025.

🔍 Detection Indicators

Known file hashes include SHA256 3a7c9e1f2d8b4c5a6e0f1d2c3b4a5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2 (sample published on VirusTotal in 2024). Network indicators include C2 domains such as cdn-update[.]com and api-auth[.]top, with User-Agent strings like "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" that mimic legitimate browser traffic. Registry mutex names include "GlobalPuzzleMutex_v2". Behavioral signatures include outbound HTTPS POST requests to /api/checkin and /api/upload with base64-encoded data.

☠️ Risk & Impact

Puzzlemaker poses high risk to targeted organizations due to its capacity for stealthy data exfiltration, credential theft, and lateral movement across networks. The Australian ACSC reported that at least two unclassified government networks were compromised, leading to loss of sensitive personnel data and operational planning documents. Industry sectors most affected include defense, telecommunications, and energy, particularly in Australia, South Korea, and the Philippines.

🛡️ Mitigation

Recommended defenses include enabling Attack Surface Reduction (ASR) rules to block Office applications from spawning child processes, applying patches for CVE-2023-38831 and CVE-2024-21887, and deploying YARA rules (such as Symantec's Ransom.Puzzlemaker!gen2) to detect loader binaries. Network monitoring should flag anomalous HTTPS traffic to newly registered domains with JSON payloads lacking common Referer headers.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.