Gallmaker

MITRE ATT&CK: G0084 View on attack.mitre.org

Aliases: Gallmaker

First seen
2017-12-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 11:56:28

Targeted industries: defense-and-aerospace government-and-public-sector

Context

Gallmaker is a cyberespionage group that has targeted victims in the Middle East and has been active since at least December 2017. The group has mainly targeted victims in the defense, military, and government sectors.

Detection coverage

  • 326 Sigma rules

Malware & tools used

  • Malicious File (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Dynamic Data Exchange (attack-pattern)
  • PowerShell (attack-pattern)
  • Spearphishing Attachment (attack-pattern)

Reports & references

  • Broadcom/Symantec — Gallmaker Attack Group (report)
  • MITRE ATT&CK — G0084 (report)

External references