GALLIUM
Aliases: Granite Typhoon
GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers. Security researchers have identified GALLIUM as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.
Open interactive actor investigation
ATT&CK techniques
T1059.003
Windows Command ShellT1003.002
Security Account ManagerT1078
Valid AccountsT1053.005
Scheduled TaskT1027
Obfuscated Files or InformationT1553.002
Code SigningT1041
Exfiltration Over C2 ChannelT1005
Data from Local SystemT1574.002
DLL Side-LoadingT1588.002
ToolT1047
Windows Management InstrumentationT1136.002
Domain AccountT1583.004
ServerT1133
External Remote ServicesT1027.002
Software PackingT1505.003
Web ShellT1003.001
LSASS MemoryT1560.001
Archive via UtilityT1059.001
PowerShellT1570
Lateral Tool TransferT1027.005
Indicator Removal from ToolsT1090.002
External ProxyT1049
System Network Connections DiscoveryT1074.001
Local Data StagingT1033
System Owner/User DiscoveryT1190
Exploit Public-Facing ApplicationT1016
System Network Configuration DiscoveryT1105
Ingress Tool TransferT1018
Remote System DiscoveryT1550.002
Pass the HashT1036.003
Rename System Utilities
Windows Command ShellT1003.002
Security Account ManagerT1078
Valid AccountsT1053.005
Scheduled TaskT1027
Obfuscated Files or InformationT1553.002
Code SigningT1041
Exfiltration Over C2 ChannelT1005
Data from Local SystemT1574.002
DLL Side-LoadingT1588.002
ToolT1047
Windows Management InstrumentationT1136.002
Domain AccountT1583.004
ServerT1133
External Remote ServicesT1027.002
Software PackingT1505.003
Web ShellT1003.001
LSASS MemoryT1560.001
Archive via UtilityT1059.001
PowerShellT1570
Lateral Tool TransferT1027.005
Indicator Removal from ToolsT1090.002
External ProxyT1049
System Network Connections DiscoveryT1074.001
Local Data StagingT1033
System Owner/User DiscoveryT1190
Exploit Public-Facing ApplicationT1016
System Network Configuration DiscoveryT1105
Ingress Tool TransferT1018
Remote System DiscoveryT1550.002
Pass the HashT1036.003
Rename System Utilities