Gallmaker

Also known as: Gallmaker

Gallmaker is a cyberespionage group that has targeted victims in the Middle East and has been active since at least December 2017. The group has mainly targeted victims in the defense, military, and government sectors. Symantec Gallmaker Oct 2018

🧭 ATT&CK G0084

Introduction

Gallmaker is a cyberespionage group that has targeted victims in the Middle East and has been active since at least December 2017. The group has mainly targeted victims in the defense, military, and government sectors. Symantec Gallmaker Oct 2018

Activities and Tactics

Information pending cataloguing.

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • Unknown Logger
  • CyberGate
  • Cyber Eye RAT
  • Archelaus Beta

Attribution and Evidence

Information pending cataloguing.

References

[1] mitre-attack [3] Symantec Gallmaker Oct 2018 Symantec Security Response. (2018, October 10). Gallmaker: New Attack Group Eschews Malware to Live off the Land. Retrieved November 27, 2018.