ATT&CKReferencesSymantec Gallmaker Oct 2018

Symantec Gallmaker Oct 2018

Symantec Security Response. (2018, October 10). Gallmaker: New Attack Group Eschews Malware to Live off the Land. Retrieved November 27, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples6

TechniqueUsed byProcedure example
T1027
Obfuscated Files or Information
GroupGallmaker

Gallmaker obfuscated shellcode used during execution.

T1059.001
PowerShell
GroupGallmaker

Gallmaker used PowerShell to download additional payloads and for execution.

T1204.002
Malicious File
GroupGallmaker

Gallmaker sent victims a lure document with a warning that asked victims to “enable content” for execution.

T1559.002
Dynamic Data Exchange
GroupGallmaker

Gallmaker attempted to exploit Microsoft’s DDE protocol in order to gain access to victim machines and for execution.

T1560.001
Archive via Utility
GroupGallmaker

Gallmaker has used WinZip, likely to archive data prior to exfiltration.

T1566.001
Spearphishing Attachment
GroupGallmaker

Gallmaker sent emails with malicious Microsoft Office documents attached.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.