Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Gallmaker

Description

Gallmaker is a cyberespionage group that has targeted victims in the Middle East and has been active since at least December 2017. The group has mainly targeted victims in the defense, military, and government sectors.(Citation: Symantec Gallmaker Oct 2018)

AI Analysis

· 1 week ago

Executive Summary

Gallmaker is a cyberespionage threat actor targeting Middle Eastern defense, military, and government sectors since at least December 2017. The group employs advanced persistent threat (APT) tactics, including spearphishing and malicious file deployments, to infiltrate victim networks and exfiltrate sensitive data.

Goals & Targeting

Gallmaker's strategic objectives appear focused on intelligence gathering from defense and military sectors in the Middle East. The group likely seeks sensitive information for political or strategic advantage, targeting countries where such data is critical. Their focus on government and military suggests a geopolitical agenda aligned with espionage goals.

Enhanced Description

Gallmaker is a cyberespionage group that has been active since December 2017, primarily targeting defense, military, and government sectors in the Middle East. The group's activities have included deploying malicious files and leveraging PowerShell for execution, as well as using-archive utilities to hide their operations. These tactics suggest a high level of technical proficiency, aligning with advanced persistent threat (APT) groups.

Key Capabilities

  • Spearphishing campaigns
  • Malicious file deployments
  • PowerShell-based execution
  • Obfuscation techniques
  • Dynamic data exchange (DDE)
  • Archive utilities for hiding malicious content

MITRE ATT&CK Tactics

Intrusion
Exfiltration
Persistence

Campaigns & Victims

Gallmaker's campaigns involve targeted attacks using spearphishing attachments and malicious Office documents. The group operates with moderate frequency, focusing on long-term access to exfiltrate data. While specific campaign details are limited, their TTPs align with those observed in APT groups targeting Middle Eastern governments.

IOC Patterns

  • Spear-phishing emails with malicious附件
  • Malicious file executions via PowerShell and VBA macros
  • Archive files for payload delivery
  • Exfiltration channels

Recommended Actions

  • Monitor network traffic for known TTPs of APT groups.
  • Implement strong email filtering to detect spearphishing attempts.
  • Regularly update software to mitigate vulnerabilities exploited by APTs.
  • Enhance user training on identifying suspicious emails and attachments.

Suggested Tags

APT
Cyberespionage
Middle East
Defense Sector

Confidence Assessment

Low confidence in the completeness of Gallmaker's targeting profile. Additional information about their TTPs, specific campaigns, and tools would enhance understanding. Limited data on group motivation and long-term objectives.

Intel Summary

6

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

4

Tactics

Tags

APT
Government Targeting
Cyberespionage
Middle East
Defense Sector

Details

MITRE ID
G0084
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--2fd2be6a-d3a2-4a65-b499-05ea2693abee
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.