logo

Gallmaker: New Attack Group Eschews Malware to Live off the Land

ID: 998fc3d4-fad2-4f6a-bb4e-873b585bf039

STIX ID: report--998fc3d4-fad2-4f6a-bb4e-873b585bf039

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2018-10-16

Last Modified Date: 2018-10-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec researchers disclose the 'Gallmaker' campaign, an espionage-focused threat actor active since at least December 2017 that avoids custom malware by using living-off-the-land techniques and publicly available tools. The group gains initial access via DDE-based malicious Office documents, runs PowerShell-based obfuscated shellcode to download Meterpreter reverse_tcp payloads, communicates with identified C2 IPs, targets government/military/embassy victims, and leaves limited disk artifacts to evade detection; the report includes IoCs, filenames, and mitigation guidance.