Overview 3 indicators
Gallmaker is a cyberespionage group that has targeted victims in the Middle East and has been active since at least December 2017. The group has mainly targeted victims in the defense, military, and government sectors.
| url | 3 | G0084.json |
Techniques 6 ATT&CK
Open in ATT&CK Navigator → or download the layer (6 techniques, layer 4.5)
- T1027 Obfuscated Files or Information
- T1059.001 PowerShell
- T1204.002 Malicious File
- T1559.002 Dynamic Data Exchange
- T1560.001 Archive via Utility
- T1566.001 Spearphishing Attachment
Principal sources 2 reports
Ranked by how many of this actor's indicators each report brought in.
- 3symantec.com/blogs/threat-intelligence/gallmaker-att…
- 3securityaffairs.co/wordpress/77041/apt/gallmaker-apt-emerg…
Timeline 3 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
3 shown
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
symantec.com/blogs/threat-intelligence/gallmaker-att… · securityaffairs.co/wordpress/77041/apt/gallmaker-apt-emerg…
111.90.149.99/o2 94.140.116.124/o2 94.140.116.231/o2