31
Techniques
16
Toolsets
2
CVEs Referenced
1
KEV Entries
CISA Known Exploited
About GALLIUM

GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers. Security researchers have identified GALLIUM as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.

View MITRE record ↗

Toolsets (16)
🐛
Malware · Windows
🐛
Malware · Windows
🐛
PingPull S1031
Malware · Windows
🐛
PlugX S0013
Malware · Windows
🐛
PoisonIvy S0012
Malware · Windows
🔧
HTRAN S0040
Tool · Linux, Windows
🔧
Mimikatz S0002
Tool · Windows
🔧
NBTscan S0590
Tool · Windows, Linux, macOS
🔧
Net S0039
Tool · Windows
🔧
Ping S0097
Tool
🔧
PsExec S0029
Tool · Windows
🔧
Reg S0075
Tool · Windows
🔧
Tool · Windows
🔧
at S0110
Tool · Linux, Windows, macOS
🔧
cmd S0106
Tool · Windows
🔧
ipconfig S0100
Tool
CVEs Referenced (2 · 1 CISA KEV)
CVE-2014-7169View full details on NVDKEV
CVE-2016-6662View full details on NVD
↑