GALLIUM
Also reported as Granite Typhoon, Alloy Taurus, PHANTOM PANDA, Red Dev 4, Operation Soft Cell and 2 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1190 6 reports in ATT&CK
- T1016 5 reports in ATT&CK
- T1059.001 4 reports in ATT&CK
- T1059.003 4 reports in ATT&CK
- T1018 3 reports in ATT&CK
- T1021.001 3 reports reports only
- T1047 3 reports in ATT&CK
- T1057 3 reports reports only
- T1105 3 reports in ATT&CK
- T1219 3 reports reports only
Show all 72 techniques Show fewer
- T1543.003 3 reports reports only
- T1003.001 2 reports in ATT&CK
- T1003.002 2 reports in ATT&CK
- T1003.003 2 reports reports only
- T1012 2 reports reports only
- T1048 2 reports reports only
- T1055 2 reports reports only
- T1068 2 reports reports only
- T1071 2 reports reports only
- T1071.001 2 reports reports only
- T1078.002 2 reports reports only
- T1082 2 reports reports only
- T1090.001 2 reports reports only
- T1112 2 reports reports only
- T1134.002 2 reports reports only
- T1136 2 reports reports only
- T1136.001 2 reports reports only
- T1486 2 reports reports only
- T1505.003 2 reports in ATT&CK
- T1560.001 2 reports in ATT&CK
- T1570 2 reports in ATT&CK
- T1572 2 reports reports only
- T1003 1 report reports only
- T1005 1 report in ATT&CK
- T1021 1 report reports only
- T1021.002 1 report reports only
- T1027 1 report in ATT&CK
- T1036 1 report reports only
- T1046 1 report reports only
- T1053 1 report reports only
- T1053.005 1 report in ATT&CK
- T1059.005 1 report reports only
- T1059.007 1 report reports only
- T1070.004 1 report reports only
- T1071.004 1 report reports only
- T1074.001 1 report in ATT&CK
- T1078 1 report in ATT&CK
- T1078.003 1 report reports only
- T1083 1 report reports only
- T1087.002 1 report reports only
- T1091 1 report reports only
- T1119 1 report reports only
- T1134.001 1 report reports only
- T1135 1 report reports only
- T1140 1 report reports only
- T1189 1 report reports only
- T1204 1 report reports only
- T1212 1 report reports only
- T1505.004 1 report reports only
- T1526 1 report reports only
- T1552 1 report reports only
- T1552.001 1 report reports only
- T1555.003 1 report reports only
- T1563.002 1 report reports only
- T1566 1 report reports only
- T1566.001 1 report reports only
- T1566.002 1 report reports only
- T1567 1 report reports only
- T1569.002 1 report reports only
- T1598 1 report reports only
- T1621 1 report reports only
- T1659 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2012-0158 KEV ransomware
- CVE-2013-4979
- CVE-2014-0160 KEV
- CVE-2014-0497 KEV
- CVE-2014-4114 KEV
- CVE-2014-6352 KEV
- CVE-2014-8439 KEV
- CVE-2015-0062
- CVE-2015-1701 KEV ransomware
- CVE-2015-2291 KEV ransomware
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
Show all 131 CVEs Show fewer
- CVE-2015-2545 KEV
- CVE-2015-3105
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2015-7645 KEV ransomware
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0099 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-1019 KEV ransomware
- CVE-2016-4117 KEV ransomware
- CVE-2016-5195 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-11882 KEV ransomware
- CVE-2017-5638 KEV ransomware
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-8759 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-4878 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8373 KEV
- CVE-2018-8440 KEV ransomware
- CVE-2018-8639 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-11539 KEV ransomware
- CVE-2019-1322 KEV ransomware
- CVE-2019-1405 KEV ransomware
- CVE-2019-1458 KEV ransomware
- CVE-2019-1579 KEV ransomware
- CVE-2019-16098
- CVE-2019-16920 KEV
- CVE-2019-19781 KEV ransomware
- CVE-2019-3396 KEV ransomware
- CVE-2019-5591 KEV ransomware
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-10189 KEV
- CVE-2020-1040 KEV
- CVE-2020-11899 KEV
- CVE-2020-12641 KEV
- CVE-2020-1350 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-17144 KEV
- CVE-2020-3125
- CVE-2020-35730 KEV
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-7961 KEV
- CVE-2020-8515 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-20016 KEV ransomware
- CVE-2021-22555 KEV
- CVE-2021-22893 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-27857
- CVE-2021-27876 KEV ransomware
- CVE-2021-27877 KEV ransomware
- CVE-2021-27878 KEV ransomware
- CVE-2021-29855
- CVE-2021-30116 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35464 KEV ransomware
- CVE-2021-36934 KEV
- CVE-2021-36942 KEV ransomware
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-41379 KEV ransomware
- CVE-2021-44026 KEV
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-24521 KEV ransomware
- CVE-2022-27926 KEV
- CVE-2022-30190 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41080 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-48503 KEV
- CVE-2022-49475
- CVE-2023-21746
- CVE-2023-22518 KEV ransomware
- CVE-2023-22527 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-24880 KEV ransomware
- CVE-2023-32315 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2023-43000 KEV
- CVE-2024-23222 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-7262 KEV
- CVE-2024-7263
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ghost RAT (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CHINACHOPPER (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Poison Ivy (Malware Family)
Show all 222 reports Show fewer
-
Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
The title opens archive.today, not the publisher’s page. Archived copy on ORKL Detailsfor Wirtschaftsspionage gegen Volkwagen: VW-Konzern wurde jahrelang ausge…
-
Chinese hackers use new Linux malware variants for espionage
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese hackers use new Linux malware variants for espionage
-
Chinese Alloy Taurus Updates PingPull Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Alloy Taurus Updates PingPull Malware
-
Operation Tainted Love - Chinese APTs Target Telcos in New Attacks
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Tainted Love - Chinese APTs Target Telcos in New Attacks
-
Conceptualizing a Continuum of Cyber Threat Attribution
The original link failed its last check. Original publisher Detailsfor Conceptualizing a Continuum of Cyber Threat Attribution
-
Russian Ransomware C2 Network Discovered in Censys Data
The original link failed its last check. Original publisher Detailsfor Russian Ransomware C2 Network Discovered in Censys Data
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool
-
Tinker Telco Soldier Spy (to be given 2022-06-27)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tinker Telco Soldier Spy (to be given 2022-06-27)
-
APT_trends_report_Q2_2022_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2022_Securelist
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
DeadRinger_ Exposing Chinese Threat Actors Targeting Major Telcos
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor DeadRinger_ Exposing Chinese Threat Actors Targeting Major Telcos
-
DeadRinger- Exposing Chinese Threat Actors Targeting Major Telcos
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor DeadRinger- Exposing Chinese Threat Actors Targeting Major Telcos
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Active Directory 侵害と推奨対策
-
Incident readiness: preparing a proactive response to attacks
The original link failed its last check. Original publisher Detailsfor Incident readiness: preparing a proactive response to attacks
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tinker Telco Soldier Spy
-
GALLIUM- Targeting global telecom
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GALLIUM- Targeting global telecom
-
GALLIUM_ Targeting global telecom
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor GALLIUM_ Targeting global telecom
-
Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers
-
China Chopper still active 9 years later
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor China Chopper still active 9 years later
-
China Chopper still active 9 years later
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China Chopper still active 9 years later
-
OPERATION SOFT CELL- A WORLDWIDE CAMPAIGN AGAINST TELECOMMUNICATIONS PROVIDERS
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OPERATION SOFT CELL- A WORLDWIDE CAMPAIGN AGAINST TELECOMMUNICATIONS PROVIDERS
-
Operation Soft Cell_ A Worldwide Campaign Against Telecommunications Providers
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Soft Cell_ A Worldwide Campaign Against Telecommunications Providers
-
BSides IR in Heterogeneous Environment
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor BSides IR in Heterogeneous Environment
-
Uncovering the Seven Pointed Dagger
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Uncovering the Seven Pointed Dagger
-
APT34 Deploys Phishing Attack With New Malware
The original link failed its last check. Original publisher Detailsfor APT34 Deploys Phishing Attack With New Malware
Newest first. Details opens the report in Explore.