GALLIUM — APT Profile
GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers. Security researchers have identified GALLIUM as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.Also tracked as
Granite Typhoon
Tools & malware
- at Execution
- BlackMould Backdoor
- China Chopper Web Shell
- cmd Execution
- HTRAN Tunneling Tool
- ipconfig Network Reconnaissance
- Mimikatz Credential Harvesting
- NBTscan Network Reconnaissance
- Net Network Reconnaissance
- Ping Network Reconnaissance
- PingPull Backdoor
- PlugX Backdoor
- PoisonIvy Remote Access Trojan
- PsExec Remote Execution
- Reg LOLBin
- Windows Credential Editor Credential Harvesting