GALLIUM

MITRE ATT&CK: G0093 View on attack.mitre.org

Aliases: Granite Typhoon, Red Dev 4, Alloy Taurus, PHANTOM PANDA, GALLIUM, Operation Soft Cell

First seen
2012-01-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
4 (2 malicious)
Last IoC activity
2026-09-01 00:34:49
Profile updated
2026-07-07 12:33:03

Targeted industries: technology-and-telecommunications financial-services government-and-public-sector

Targeted regions: country_code:af country_code:au country_code:be country_code:kh country_code:my country_code:mz country_code:ph country_code:ru country_code:vn

Context

GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers. Security researchers have identified GALLIUM as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.

Recent IoC activity

2 malicious indicators in Maltiverse are attributed to GALLIUM (G0093). The 2 most recently updated:

TypeIndicatorUpdatedSources
hostname saspecialforces.co.za 2026-09-02 1
file sample f86ebeb6b3c7f12ae98fe278df707d9ebdc17b19be0c773309f9af599243d0a3.exe 2026-02-26 2

Detection coverage

  • 26 YARA rules
  • 912 Sigma rules

Malware & tools used

  • Windows Command Shell (attack-pattern)
  • Security Account Manager (attack-pattern)
  • Valid Accounts (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Code Signing (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Data from Local System (attack-pattern)
  • DLL (attack-pattern)
  • Tool (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Domain Account (attack-pattern)
  • Server (attack-pattern)
  • External Remote Services (attack-pattern)
  • Software Packing (attack-pattern)
  • Web Shell (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Archive via Utility (attack-pattern)
  • PowerShell (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Indicator Removal from Tools (attack-pattern)
  • External Proxy (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Local Data Staging (attack-pattern)
  • System Owner/User Discovery (attack-pattern)

Related threat objects

Reports & references

  • cybereason.com — Operation Soft Cell A Worldwide Campaign Against Telecommunications Providers (report)
  • Microsoft — Gallium Targeting Global Telecom (report)
  • youtube.com — Watch (report)
  • troopers.de — 7Cv8Pz (report)
  • Palo Alto Unit 42 — Alloytaurus (report)
  • Palo Alto Unit 42 — Alloy Taurus Targets Se Asian Government (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • MITRE ATT&CK — G0093 (report)
  • Palo Alto Unit 42 — Pingpull Gallium (report)

External references