GALLIUM — APT Profile
GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers. Security researchers have identified GALLIUM as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
Granite Typhoon, Red Dev 4, Alloy Taurus, PHANTOM PANDA
Tools & malware
- at Execution
- BlackMould Backdoor
- China Chopper Web Shell
- cmd Execution
- HTRAN Tunneling Tool
- ipconfig Network Reconnaissance
- Mimikatz Credential Harvesting
- NBTscan Network Reconnaissance
- Net Network Reconnaissance
- Ping Network Reconnaissance
- PingPull Backdoor
- PlugX Backdoor
- PoisonIvy Remote Access Trojan
- PsExec Remote Execution
- Reg LOLBin
- Windows Credential Editor Credential Harvesting
Vendor research
- How Microsoft names threat actors Microsoft
- Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers Cybereason
- GALLIUM: Targeting global telecom Microsoft
- GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool Unit 42
Countries linked to this actor
- Belgium targets
- Cambodia targets
- Afghanistan targets