ATT&CKGroupsGallmaker

Gallmaker

G0084

Threat group.View on attack.mitre.org

About this group

Gallmaker is a cyberespionage group that has targeted victims in the Middle East and has been active since at least December 2017. The group has mainly targeted victims in the defense, military, and government sectors.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027
Obfuscated Files or Information

Gallmaker obfuscated shellcode used during execution.

T1059.001
PowerShell

Gallmaker used PowerShell to download additional payloads and for execution.

T1204.002
Malicious File

Gallmaker sent victims a lure document with a warning that asked victims to “enable content” for execution.

T1559.002
Dynamic Data Exchange

Gallmaker attempted to exploit Microsoft’s DDE protocol in order to gain access to victim machines and for execution.

T1560.001
Archive via Utility

Gallmaker has used WinZip, likely to archive data prior to exfiltration.

T1566.001
Spearphishing Attachment

Gallmaker sent emails with malicious Microsoft Office documents attached.

Software0

None recorded.

Campaigns0

None recorded.

References1

  1. Symantec Gallmaker Oct 2018 Open source
    Symantec Security Response. (2018, October 10). Gallmaker: New Attack Group Eschews Malware to Live off the Land. Retrieved November 27, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.