Introduction
Gallmaker is a cyberespionage group that has targeted victims in the Middle East and has been active since at least December 2017. The group has mainly targeted victims in the defense, military, and government sectors. Symantec Gallmaker Oct 2018
Activities and Tactics
Information pending cataloguing.
Notable Campaigns
Information pending cataloguing.
Tactics, Techniques, and Procedures (TTPs)
- T1204.002 Malicious File
- T1027 Obfuscated Files or Information
- T1560.001 Archive via Utility
- T1559.002 Dynamic Data Exchange
- T1059.001 PowerShell
- T1566.001 Spearphishing Attachment
ATT&CK technique IDs (denormalized)
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- Unknown Logger
- CyberGate
- Cyber Eye RAT
- Archelaus Beta
Attribution and Evidence
Information pending cataloguing.
References
[1] mitre-attack [3] Symantec Gallmaker Oct 2018 Symantec Security Response. (2018, October 10). Gallmaker: New Attack Group Eschews Malware to Live off the Land. Retrieved November 27, 2018.