Gallmaker

Threat Actor updated 5 months ago (2024-05-04T16:41:29.109Z)
Download STIX
Preview STIX
Gallmaker, a threat actor group we have been monitoring since its inception in December 2017, has exhibited consistent activity up until June 2018. The group's operations are characterized by a unique approach of not using custom malware but instead leveraging "living off the land" (LotL) tactics and publicly available hacking tools. This strategy makes Gallmaker's activities particularly challenging to detect, as they blend with legitimate processes and use widely accessible tools, thereby leaving minimal traces of intrusion. The group's activity points strongly towards cyber espionage, likely sponsored by a state entity, given the nature of their targets. Gallmaker's victims are primarily associated with government, military, or defense sectors, indicating a highly targeted approach. The group uses three primary IP addresses for its command-and-control (C&C) infrastructure to communicate with infected devices. Notably, the victims observed lacked a specific patch, rendering them vulnerable to exploits via the DDE protocol. Despite the stealthy nature of Gallmaker's activities, Symantec's Targeted Attack Analytics (TAA) technology was instrumental in detecting this threat actor. Gallmaker's reliance on LotL tactics and public hack tools, combined with their focus on high-value governmental and defense targets, underscores the evolving sophistication of threat actors and the need for advanced detection capabilities. It also emphasizes the importance of regular system updates and patches in maintaining a strong security posture.
Description last updated: 2023-11-29T05:32:43.088Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Gallmaker Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
MITRE
2 years ago