October 19, 2018 By David Bisson < 1 min read

Security researchers observed a new attack group known as Gallmaker using living-off-the-land (LotL) tactics in an extensive espionage campaign.

According to Symantec, the attackers targeted several embassies of an Eastern European country, defense targets in the Middle East, and other government and military targets. The threat group — which has been in operation since at least December 2017 — did not use malware as part of its most recent activity. Instead, it employed LotL tactics and publicly available hacking tools.

In the campaigns discovered by Symantec, Gallmaker sent out spear phishing emails with malicious attachments. These documents abused the Microsoft Office Dynamic Data Exchange (DDE) protocol to compromise recipients’ machines. The attackers then leveraged that access to spy on their victims by remotely executing commands in memory, including the use of WindowsRoamingToolsTask to schedule PowerShell scripts and a “reverse_tcp” reverse shell payload from Metasploit.

A Surge in Living-off-the-Land Tactics

Gallmaker isn’t the only group that has used LotL tactics in recent months. In fact, Symantec researchers witnessed a surge in these techniques dating back to at least July 2017.

At the time, they identified four main categories of LotL attacks, including the abuse of dual-use tools such as PsExec and the emergence of memory-only threats that may achieve fileless persistence. Symantec also noted that those behind the June 2017 Petya outbreak had lived off the land as a means to infect organizations around the world.

How to Defend Against Gallmaker Attacks

Security professionals can protect their organizations against Gallmaker’s campaigns by establishing a consistent software patching program that prioritizes vulnerabilities based on their assessed risk. Security teams should also adhere to the principle of layered security and implement next-generation endpoint protection tools to defend against fileless malware.

Sources: Symantec, Symantec(1)

More from

Cloud Threat Landscape Report: AI-generated attacks low for the cloud

2 min read - For the last couple of years, a lot of attention has been placed on the evolutionary state of artificial intelligence (AI) technology and its impact on cybersecurity. In many industries, the risks associated with AI-generated attacks are still present and concerning, especially with the global average of data breach costs increasing by 10% from last year.However, according to the most recent Cloud Threat Landscape Report released by IBM’s X-Force team, the near-term threat of an AI-generated attack targeting cloud computing…

Testing the limits of generative AI: How red teaming exposes vulnerabilities in AI models

4 min read - With generative artificial intelligence (gen AI) on the frontlines of information security, red teams play an essential role in identifying vulnerabilities that others can overlook.With the average cost of a data breach reaching an all-time high of $4.88 million in 2024, businesses need to know exactly where their vulnerabilities lie. Given the remarkable pace at which they’re adopting gen AI, there’s a good chance that some of those vulnerabilities lie in AI models themselves — or the data used to…

FBI, CISA issue warning for cross Apple-Android texting

3 min read - CISA and the FBI recently released a joint statement that the People's Republic of China (PRC) is targeting commercial telecommunications infrastructure as part of a significant cyber espionage campaign. As a result, the agencies released a joint guide, Enhanced Visibility and Hardening Guidance for Communications Infrastructure, with best practices organizations and agencies should adopt to protect against this espionage threat. According to the statement, PRC-affiliated actors compromised networks at multiple telecommunication companies. They stole customer call records data as well…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today