Also known as: Granite Typhoon, Red Dev 4, Alloy Taurus, PHANTOM PANDA
GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers.(Citation: Cybereason Soft Cell June 2019) Security researchers have identified GALLIUM as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.(Citation: Cybereason Soft Cell June 2019)(Citation: Microsoft GALLIUM December 2019)(Citation: Unit 42 PingPull Jun 2022)
Soft Cell
Targeted Sectors
Executive Summary
GALLIUM, also known as Granite Typhoon, Red Dev 4, Alloy Taurus, and PHANTOM PANDA, is a cyberespionage group active since at least 2012. The group primarily targets telecommunications companies, financial institutions, and government entities across Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. GALLIUM is suspected to be a state-sponsored Chinese threat actor based on its tools and tactics, with notable operations such as Operation Soft Cell targeting telecommunications providers.
Goals & Targeting
GALLIUM's strategic objectives appear to be primarily focused on espionage, targeting sectors that hold sensitive information such as telecommunications, finance, and government. The group's targeting profile suggests a focus on countries with significant geopolitical interests or where influence can be maximized through cyberespionage activities. The choice of victims indicates an intent to gather classified information, disrupt critical infrastructure, or gain strategic advantages.
Enhanced Description
GALLIUM is a persistent cyberespionage group that has been operational since at least 2012, with primary focus on telecommunications companies, financial institutions, and government entities. The group's activities span multiple countries including Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. GALLIUM is known for its long-term campaign Operation Soft Cell, which targeted telecommunications providers. Security researchers have identified the group as likely Chinese state-sponsored, based on tools used and tactics commonly associated with Chinese threat actors. This includes tools such as PingPull, China Chopper, BlackMould, PlugX, and PoisonIvy, which are indicative of a well-resourced and sophisticated adversary.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GALLIUM is known for Operation Soft Cell, a long-term campaign targeting telecommunications providers. The group employs sophisticated techniques such as scheduled tasks, archive utilities, and external remote services to achieve persistence and data exfiltration. Campaign patterns include initial access via phishing or exploit of public-facing applications, followed by lateral movement within networks using tools like PlugX and PoisonIvy. Recent observations suggest increased focus on Southeast Asian countries, with campaigns extending into 2023.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the classification of GALLIUM as a Chinese state-sponsored threat actor, based on toolset and TTPs. However, gaps exist regarding the full scope of its campaign patterns post-2022 and evidence of direct links to Chinese government entities beyond technical indicators.
Soft Cell
No observed data linked yet.
No IOCs linked yet.
31
Techniques
11
Tools
1
Campaigns
0
IOCs
0
Observed Data
12
Tactics