{"id":3068,"date":"2021-06-14T22:28:40","date_gmt":"2021-06-15T03:28:40","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3068"},"modified":"2021-06-14T22:28:41","modified_gmt":"2021-06-15T03:28:41","slug":"puzzlemaker-a-group-that-targets-windows-10","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/","title":{"rendered":"PuzzleMaker &#8211; A group that targets Windows 10"},"content":{"rendered":"\n<p>Kaspersky security researchers discovered a new threat actor named PuzzleMaker, which has used a string of zero-day exploits from Google Chrome and Windows 10 in highly targeted attacks against various companies around the world. According to Kaspersky, the attacks coordinated by PuzzleMaker were first detected in mid-April, when the networks of the first victims were compromised.<\/p>\n\n\n\n<p>The zero-day exploit chain deployed in the campaign used a remote code execution vulnerability in the Google Chrome V8 JavaScript engine to access target systems. In addition, it was identified that the first exploit in the chain, although not confirmed, appears to be CVE-2021-21224, a V8 confusion vulnerability in the Google Chrome browser prior to 90.0.4430.85.<\/p>\n\n\n\n<p>Google issued a patch for the severe flaw on April 20, which if exploited, allowed remote attackers to execute arbitrary code inside a sandbox through a crafted HTML page. This isn&#8217;t the first string of Chrome zero-day exploits used in the wild in recent months. Project Zero, Google&#8217;s zero-day bug search team, revealed a large-scale operation in which a group of hackers used 11 zero days to attack Windows, iOS and Android users in a single year.<\/p>\n\n\n\n<p>Project Zero researchers collected a large amount of information from the exploit servers used in the two campaigns, including:<\/p>\n\n\n\n<p><strong><em>\u25b8Two sandbox escape exploits that abuse three day 0 vulnerabilities in Windows<\/em><\/strong><\/p>\n\n\n\n<p>Sandboxes, by design, are intended for developer, testing, and protection environments, thus separating the activities of a main system. For a chain of exploits to work, an escape from the sandbox would be the next necessary step.<\/p>\n\n\n\n<p><strong><em>\u25b8Renderer exploits for four bugs in Chrome, one of which was still a day 0 at the time of discovery<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8 Privilege escalation kit made up of publicly known n-day exploits for older versions of Android<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8A complete exploit chain targeting Windows 10 fully patched using Google Chrome<\/em><\/strong><\/p>\n\n\n\n<p><strong><em>\u25b8Two partial strings targeting 2 different fully patched Android devices running Android 10 using Google Chrome and Samsung browser<\/em><\/strong><\/p>\n\n\n\n<p>Organizations are encouraged to maintain frequent patch schedules and apply relevant fixes, even more so if bugs are actively exploited. As we saw with the Microsoft Exchange Server incident in March, attackers will quickly address security issues as soon as they are publicly known.<\/p>\n\n\n\n<p>Also check:<br><a href=\"https:\/\/truxgoservers.com\/blog\/siloscape-is-the-first-threat-to-attack-windows-containers\/\">Siloscape is the first threat to attack Windows containers<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/vovalex-ransomware-posing-as-windows-utilities\/\">Vovalex \u2013 Ransomware posing as Windows utilities<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Kaspersky security researchers discovered a new threat actor named PuzzleMaker, which has used a string of zero-day exploits from Google Chrome and Windows 10 in highly targeted attacks against various companies around the world. According to Kaspersky, the attacks coordinated by PuzzleMaker were first detected in mid-April, when the networks of the first victims were [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3069,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-3068","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>PuzzleMaker - A group that targets Windows 10 - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"Cybercriminal groups are always active as we well know and now comes one of these groups known as PuzzleMaker which we will see today.....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PuzzleMaker - A group that targets Windows 10 - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"Cybercriminal groups are always active as we well know and now comes one of these groups known as PuzzleMaker which we will see today.....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-06-15T03:28:40+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-06-15T03:28:41+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Puzzle.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"675\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/puzzlemaker-a-group-that-targets-windows-10\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/puzzlemaker-a-group-that-targets-windows-10\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"PuzzleMaker &#8211; A group that targets Windows 10\",\"datePublished\":\"2021-06-15T03:28:40+00:00\",\"dateModified\":\"2021-06-15T03:28:41+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/puzzlemaker-a-group-that-targets-windows-10\\\/\"},\"wordCount\":385,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/puzzlemaker-a-group-that-targets-windows-10\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Puzzle.png\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/puzzlemaker-a-group-that-targets-windows-10\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/puzzlemaker-a-group-that-targets-windows-10\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/puzzlemaker-a-group-that-targets-windows-10\\\/\",\"name\":\"PuzzleMaker - A group that targets Windows 10 - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/puzzlemaker-a-group-that-targets-windows-10\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/puzzlemaker-a-group-that-targets-windows-10\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Puzzle.png\",\"datePublished\":\"2021-06-15T03:28:40+00:00\",\"dateModified\":\"2021-06-15T03:28:41+00:00\",\"description\":\"Cybercriminal groups are always active as we well know and now comes one of these groups known as PuzzleMaker which we will see today.....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/puzzlemaker-a-group-that-targets-windows-10\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/puzzlemaker-a-group-that-targets-windows-10\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/puzzlemaker-a-group-that-targets-windows-10\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Puzzle.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/06\\\/Puzzle.png\",\"width\":1200,\"height\":675},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/puzzlemaker-a-group-that-targets-windows-10\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"PuzzleMaker &#8211; A group that targets Windows 10\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"PuzzleMaker - A group that targets Windows 10 - Truxgo Server Blog","description":"Cybercriminal groups are always active as we well know and now comes one of these groups known as PuzzleMaker which we will see today.....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/","og_locale":"es_MX","og_type":"article","og_title":"PuzzleMaker - A group that targets Windows 10 - Truxgo Server Blog","og_description":"Cybercriminal groups are always active as we well know and now comes one of these groups known as PuzzleMaker which we will see today.....","og_url":"https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-06-15T03:28:40+00:00","article_modified_time":"2021-06-15T03:28:41+00:00","og_image":[{"width":1200,"height":675,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Puzzle.png","type":"image\/png"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"PuzzleMaker &#8211; A group that targets Windows 10","datePublished":"2021-06-15T03:28:40+00:00","dateModified":"2021-06-15T03:28:41+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/"},"wordCount":385,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Puzzle.png","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/","url":"https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/","name":"PuzzleMaker - A group that targets Windows 10 - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Puzzle.png","datePublished":"2021-06-15T03:28:40+00:00","dateModified":"2021-06-15T03:28:41+00:00","description":"Cybercriminal groups are always active as we well know and now comes one of these groups known as PuzzleMaker which we will see today.....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Puzzle.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/06\/Puzzle.png","width":1200,"height":675},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/puzzlemaker-a-group-that-targets-windows-10\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"PuzzleMaker &#8211; A group that targets Windows 10"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3068","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3068"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3068\/revisions"}],"predecessor-version":[{"id":3089,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3068\/revisions\/3089"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3069"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3068"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3068"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3068"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}