Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: Granite Typhoon
31
techniques
16
software
11,228
corpus matches
profile
GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers. Security researchers have identified GALLIUM as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.
techniques
31 attributed · most-instrumented first
software
16 malware & tools attributed
Mimikatz
S0002
Windows Credential Editor
S0005
PoisonIvy
S0012
PlugX
S0013
China Chopper
S0020
PsExec
S0029
Net
S0039
HTRAN
S0040
Reg
S0075
Ping
S0097
read this carefully
11,228 corpus matches is not attribution
That count is indicators which exhibit techniques GALLIUM is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+19 more techniques
ipconfig
S0100
cmd
S0106
at
S0110
BlackMould
S0564
NBTscan
S0590
PingPull
S1031
showing 30 of 11,228
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.