NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / GALLIUM

GALLIUM

G0093 China MITRE ATT&CK →

Also known as: Granite Typhoon

Overview

GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers. Security researchers have identified GALLIUM as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190
  • Custom malware/implant development — ATT&CK: 5 attributed custom malware families

TTPs — 31 techniques across 12 tactics

Resource Development

Initial Access

Persistence

Defense Impairment

Credential Access

Lateral Movement

Collection

Command and Control

Exfiltration

Tools & malware (16)

ipconfig · Ping · cmd · China Chopper · PoisonIvy · at · PlugX · PingPull · BlackMould · Mimikatz · Net · Reg · PsExec · HTRAN · NBTscan · Windows Credential Editor

Reporting (3)