Gallmaker: New Attack Group Eschews Malware to Live off the Land
ID: 998fc3d4-fad2-4f6a-bb4e-873b585bf039
STIX ID: report--998fc3d4-fad2-4f6a-bb4e-873b585bf039
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2018-10-16
Last Modified Date: 2018-10-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Symantec researchers disclose the 'Gallmaker' campaign, an espionage-focused threat actor active since at least December 2017 that avoids custom malware by using living-off-the-land techniques and publicly available tools. The group gains initial access via DDE-based malicious Office documents, runs PowerShell-based obfuscated shellcode to download Meterpreter reverse_tcp payloads, communicates with identified C2 IPs, targets government/military/embassy victims, and leaves limited disk artifacts to evade detection; the report includes IoCs, filenames, and mitigation guidance.
