GalaxyGato is an Iranian threat actor engaged in cyber-espionage activity. It has been observed targeting organizations in Greece and Israel, using PowerShell-based scripts to collect system information and steal credentials. The group has deployed an improved C5 backdoor and has used DLL search-order hijacking as part of credential-theft operations. Reported tradecraft indicates a focus on post-compromise collection and credential access consistent with espionage-oriented intrusion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
GalaxyGato is an Iran-aligned APT group that deployed an improved C5 backdoor and used DLL-search-order hijacking to steal credentials.
Iran-aligned operations using PowerShell-based tooling for collection and credential theft, observed targeting Greece and Israel.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.