GALLIUM
MITRE ATT&CK: G0093 View on attack.mitre.org
Aliases: Granite Typhoon, Red Dev 4, Alloy Taurus, PHANTOM PANDA, GALLIUM, Operation Soft Cell
- First seen
- 2012-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 4 (2 malicious)
- Last IoC activity
- 2026-09-01 00:34:49
- Profile updated
- 2026-07-07 12:33:03
Targeted industries: technology-and-telecommunications financial-services government-and-public-sector
Targeted regions: country_code:af country_code:au country_code:be country_code:kh country_code:my country_code:mz country_code:ph country_code:ru country_code:vn
Context
GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers. Security researchers have identified GALLIUM as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.
Recent IoC activity
2 malicious indicators in Maltiverse are attributed to GALLIUM (G0093). The 2 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | saspecialforces.co.za | 2026-09-02 | 1 |
| file sample | f86ebeb6b3c7f12ae98fe278df707d9ebdc17b19be0c773309f9af599243d0a3.exe | 2026-02-26 | 2 |
Detection coverage
- 26 YARA rules
- 912 Sigma rules
Malware & tools used
- Windows Command Shell (attack-pattern)
- Security Account Manager (attack-pattern)
- Valid Accounts (attack-pattern)
- Scheduled Task (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Code Signing (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Data from Local System (attack-pattern)
- DLL (attack-pattern)
- Tool (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Domain Account (attack-pattern)
- Server (attack-pattern)
- External Remote Services (attack-pattern)
- Software Packing (attack-pattern)
- Web Shell (attack-pattern)
- LSASS Memory (attack-pattern)
- Archive via Utility (attack-pattern)
- PowerShell (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- Indicator Removal from Tools (attack-pattern)
- External Proxy (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Local Data Staging (attack-pattern)
- System Owner/User Discovery (attack-pattern)
Related threat objects
- Operation Soft Cell (threat-actor)
Reports & references
- cybereason.com — Operation Soft Cell A Worldwide Campaign Against Telecommunications Providers (report)
- Microsoft — Gallium Targeting Global Telecom (report)
- youtube.com — Watch (report)
- troopers.de — 7Cv8Pz (report)
- Palo Alto Unit 42 — Alloytaurus (report)
- Palo Alto Unit 42 — Alloy Taurus Targets Se Asian Government (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- MITRE ATT&CK — G0093 (report)
- Palo Alto Unit 42 — Pingpull Gallium (report)