Gallmaker
Overview
Gallmaker is a cyberespionage group that has targeted victims in the Middle East and has been active since at least December 2017. The group has mainly targeted victims in the defense, military, and government sectors.
Naming & attribution
Gallmaker is tracked under 1 names across the industry. It uses 6 documented ATT&CK techniques — more than 17% of the 174 groups tracked here.
| Name | First reported by |
|---|---|
| Gallmaker | Symantec Security Response |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- TA459 China — 3 shared techniques (38% overlap)
- DarkHydrus — 3 shared techniques (30% overlap)
- Nomadic Octopus Russia — 3 shared techniques (30% overlap)
- Tonto Team China — 3 shared techniques (17% overlap)
- BITTER — 3 shared techniques (16% overlap)
- Gorgon Group Pakistan — 3 shared techniques (16% overlap)
TTPs — 6 techniques across 4 tactics
Initial Access
-
T1566.001Spearphishing Attachment
Execution
-
T1059.001PowerShell -
T1204.002Malicious File -
T1559.002Dynamic Data Exchange
Stealth
Collection
-
T1560.001Archive via Utility
Reporting (1)
- Gallmaker: New Attack Group Eschews Malware to Live off the Land — Symantec Security Response