Symantec Security Response. (2018, October 10). Gallmaker: New Attack Group Eschews Malware to Live off the Land. Retrieved November 27, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027 Obfuscated Files or Information |
GroupGallmaker | Gallmaker obfuscated shellcode used during execution. |
| T1059.001 PowerShell |
GroupGallmaker | Gallmaker used PowerShell to download additional payloads and for execution. |
| T1204.002 Malicious File |
GroupGallmaker | Gallmaker sent victims a lure document with a warning that asked victims to “enable content” for execution. |
| T1559.002 Dynamic Data Exchange |
GroupGallmaker | Gallmaker attempted to exploit Microsoft’s DDE protocol in order to gain access to victim machines and for execution. |
| T1560.001 Archive via Utility |
GroupGallmaker | Gallmaker has used WinZip, likely to archive data prior to exfiltration. |
| T1566.001 Spearphishing Attachment |
GroupGallmaker | Gallmaker sent emails with malicious Microsoft Office documents attached. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.