Galileo is Hacking Team’s Remote Control System (RCS) spyware platform, also referred to alongside the company’s Da Vinci platform. Hacking Team, an Italian company based in Milan, sold RCS/Galileo to governments, law enforcement agencies, and some corporate customers. The platform is described as enabling remote monitoring and covert surveillance of targets, including interception and collection of communications, files and emails, recording of Skype/VoIP communications, keystrokes, screenshots, audio, texts, call history, address books, GPS location, Wi‑Fi passwords, and cryptocurrency wallet files. It could remotely activate microphones and cameras and was designed to bypass cryptography by capturing audio/video streams from device memory during Skype sessions. Hacking Team malware payloads supported Android, BlackBerry, iOS, Linux, Mac OS X, Symbian, and Microsoft Windows/Windows Mobile/Windows Phone.
The content links Galileo to government surveillance procurement and deployment discussions in Mexico. In late 2014, reseller Grupo Tech Bull sought to replace an NSO Pegasus deal for Mexico’s PGR with Hacking Team’s Galileo, requesting quotes for 500 and 1,000 infections and emphasizing Galileo’s PC infection capability. The same material states that Estado de Mexico had previously bought Hacking Team’s Da Vinci system, and that dissatisfaction with a prior Hacking Team deployment in Toluca affected perceptions of the product.
Galileo is also mentioned in forensic reporting on the 2018 compromise of Jeff Bezos’s phone. Experts assessed that the most likely explanation for anomalous data egress was mobile spyware such as NSO Group’s Pegasus or, less likely, Hacking Team’s Galileo. In that context, such spyware was described as capable of hooking into legitimate applications to bypass detection and obfuscate activity.
Hacking Team and its RCS platforms were widely criticized for sales to governments with poor human-rights records, including Sudan, Bahrain, Venezuela, and Saudi Arabia. The company’s internal data, source code, invoices, and emails were exposed in a major July 5, 2015 breach attributed to Phineas Fisher; the leak included operational details and an Adobe Flash zero-day, CVE-2015-5119. The content also notes that leaked documents tied Hacking Team spyware to targeting and intimidation of Mexican journalists and that SentinelLABS later reported a Turkish threat actor, EGoManiac, using Hacking Team RCS in spying activity involving Turkish police and journalists at OdaTV.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The leaked tools included a zero-day exploit for Adobe Flash (CVE-2015-5119) as well as sophisticated platforms capable of providing remote access, keylogging, general information recording and exfiltration.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
AS I´VE HEARD, THE GALILEO SOLUTION IS MUCH BETTER THAN THE DA VINCI THEY HAVE IN TOLUCA.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial results did not identify the presence of any embedded malicious code, but further analysis revealed that the suspect video had been delivered via an encrypted downloader host on WhatsApp’s media server.
• Kernel rootkit. • 32 bits kernel extension: Lft2iRjk.7qa. • 64 bits kernel extension: 3ZPYmgGV.TOA.
• Sdbm hash used to “obfuscate” the symbols names. • Packed with MPRESS in two samples.
• Dynamically resolves all other required symbols. • Search for the dyld symbols that allow to retrieve loaded images.
The leaked tools included ... sophisticated platforms capable of providing remote access, keylogging, general information recording and exfiltration.
• C&C traffic over HTTP. • Encrypted data over HTTP. • REST Protocol.
RCS is a management platform that allows operators to remotely deploy exploits and payloads against targeted systems, remotely manage devices once compromised, and exfiltrate data for remote analysis.
Experts advised that the most likely explanation for the anomalous data egress was use of mobile spyware such as NSO Group’s Pegasus or, less likely, Hacking Team’s Galileo... following the initial spike of exfiltration after receipt of the suspect video file, more than 6GB of egress data was observed using exfiltration vectors.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mobile spyware mentioned as a less likely alternative explanation for the observed compromise, capable of hooking into legitimate applications to bypass detection and obfuscate activity.
Hacking Team's commercial surveillance/intrusion platform discussed as an alternative to Pegasus, with support for more infections and PC compromise.
Hacking Team RCS platform variant used for remote monitoring and data exfiltration from compromised devices.
Mobile spyware referenced as a less likely explanation for the observed anomalous data egress and exfiltration behavior on the device.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.