Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GALLIUM

Also known as: Granite Typhoon, Red Dev 4, Alloy Taurus, PHANTOM PANDA

Description

GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers.(Citation: Cybereason Soft Cell June 2019) Security researchers have identified GALLIUM as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.(Citation: Cybereason Soft Cell June 2019)(Citation: Microsoft GALLIUM December 2019)(Citation: Unit 42 PingPull Jun 2022)

TTP Summary

Soft Cell

Goals & Targeting

Targeted Sectors

Telecommunications

AI Analysis

· 2 weeks ago

Executive Summary

GALLIUM, also known as Granite Typhoon, Red Dev 4, Alloy Taurus, and PHANTOM PANDA, is a cyberespionage group active since at least 2012. The group primarily targets telecommunications companies, financial institutions, and government entities across Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. GALLIUM is suspected to be a state-sponsored Chinese threat actor based on its tools and tactics, with notable operations such as Operation Soft Cell targeting telecommunications providers.

Goals & Targeting

GALLIUM's strategic objectives appear to be primarily focused on espionage, targeting sectors that hold sensitive information such as telecommunications, finance, and government. The group's targeting profile suggests a focus on countries with significant geopolitical interests or where influence can be maximized through cyberespionage activities. The choice of victims indicates an intent to gather classified information, disrupt critical infrastructure, or gain strategic advantages.

Enhanced Description

GALLIUM is a persistent cyberespionage group that has been operational since at least 2012, with primary focus on telecommunications companies, financial institutions, and government entities. The group's activities span multiple countries including Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. GALLIUM is known for its long-term campaign Operation Soft Cell, which targeted telecommunications providers. Security researchers have identified the group as likely Chinese state-sponsored, based on tools used and tactics commonly associated with Chinese threat actors. This includes tools such as PingPull, China Chopper, BlackMould, PlugX, and PoisonIvy, which are indicative of a well-resourced and sophisticated adversary.

Key Capabilities

  • Spear-phishing campaigns
  • Use of custom malware and tools like PingPull, China Chopper, BlackMould, PlugX, PoisonIvy
  • Data exfiltration through C2 channels
  • Local data staging and external remote services exploitation
  • DLL injection and code signing techniques
  • Windows Management Instrumentation (WMI) usage

MITRE ATT&CK Tactics

Reconnaissance
Exfiltration
Persistence
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
External Communication

ATT&CK Techniques

T1053.005
T1560.001
T1133
T1074.001
T1003.002
T1553.002
T1574.001
T1005
T1190
T1505.003

Software / Tooling

PingPull
China Chopper
BlackMould
PlugX
PoisonIvy

Campaigns & Victims

GALLIUM is known for Operation Soft Cell, a long-term campaign targeting telecommunications providers. The group employs sophisticated techniques such as scheduled tasks, archive utilities, and external remote services to achieve persistence and data exfiltration. Campaign patterns include initial access via phishing or exploit of public-facing applications, followed by lateral movement within networks using tools like PlugX and PoisonIvy. Recent observations suggest increased focus on Southeast Asian countries, with campaigns extending into 2023.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Scheduled task creation for persistence
  • C2 communication channels
  • DLL injection
  • Use of legitimate utilities for malicious purposes

Recommended Actions

  • Implement multi-layered network monitoring to detect C2 activities and scheduled tasks.
  • Conduct regular user training to identify spear-phishing attempts.
  • Monitor for unauthorized access to sensitive systems using WMI or LSASS memory dumping techniques.
  • Apply patches and updates to mitigate known vulnerabilities exploited by the group.
  • Use endpoint detection solutions to identify malicious tools like PlugX and China Chopper.

Suggested Tags

APT
State-sponsored
Espionage
Telecommunications sector
Financial sector

Confidence Assessment

High confidence in the classification of GALLIUM as a Chinese state-sponsored threat actor, based on toolset and TTPs. However, gaps exist regarding the full scope of its campaign patterns post-2022 and evidence of direct links to Chinese government entities beyond technical indicators.

ATT&CK Techniques

Discovery
4 techniques
Stealth
6 techniques

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Cybereason Soft Cell June 2019 — Cybereason Nocturnus. (2019, June 25). Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers. Retrieved July 18, 2019.
  2. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  3. Microsoft GALLIUM December 2019 — MSTIC. (2019, December 12). GALLIUM: Targeting global telecom. Retrieved January 13, 2021.
  4. Unit 42 PingPull Jun 2022 — Unit 42. (2022, June 13). GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool. Retrieved August 7, 2022.

Intel Summary

31

Techniques

11

Tools

1

Campaigns

0

IOCs

0

Observed Data

12

Tactics

Tags

APT
Financial Targeting
Government Targeting
State-sponsored
Espionage
Telecommunications sector
Financial sector

Details

MITRE ID
G0093
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--06a11b7e-2a36-47fe-8d3e-82c265df3258
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.