Trending
ee-track">
Link copied!

Table of Contents

Gallium threat actor profile

Threat Actor Profile: Gallium

Gallium is an advanced persistent threat (APT) group associated with China and known for conducting targeted intrusions against telecommunications providers, government organizations, law-enforcement entities, and financial services organizations. The group is also tracked under the aliases Alloy Taurus, Granite Typhoon, Operation Soft Cell, and Phantom Panda, and is identified by MITRE ATT&CK as G0093. 

Gallium has been active since 2018, with its operations characterized by multi-wave campaigns designed to obtain and maintain access to targeted enterprise networks. Its activity has been particularly associated with the telecommunications sector, where the group has demonstrated an ability to exploit exposed infrastructure, establish persistent access, harvest credentials, move laterally, and collect information from compromised systems. 

Rather than relying exclusively on highly sophisticated or bespoke malware, Gallium has frequently combined commonly available malware, publicly accessible toolkits, and modified versions of existing utilities. The group has also demonstrated an emphasis on inexpensive and replaceable infrastructure, including dynamic-DNS domains and reused hop points, allowing infrastructure to be replaced without requiring substantial investment. 

Origin, Targets, and Operational Reach 

Gallium is associated with China and has primarily been observed targeting organizations where access to communications infrastructure, government networks, or other high-value enterprise environments could provide significant intelligence or operational value. 

The group’s identified target industries include three principal sectors: 

  • Banking, Financial Services and Insurance (BFSI) 
  • Government and Law Enforcement Agencies 
  • Telecommunications 

Telecommunications providers have been particularly important targets. Gallium campaigns have involved multi-wave attacks intended to compromise enterprise networks and progressively expand control once an initial foothold has been established. 

The group’s targeting methodology emphasizes exposed and inadequate patched services. In particular, Gallium has exploited publicly facing WildFly/JBoss servers to gain access to victim networks. Once inside, the group can use credential theft, legitimate administrative functionality, remote execution, and persistent accounts to expand its access. 

A representative Gallium intrusion scenario begins with reconnaissance of a telecommunications company’s externally exposed infrastructure. Threat actors scan for unpatched internet-facing services and identify vulnerable WildFly/JBoss servers. Following exploitation, they establish persistence and begin harvesting credentials, including through Mimikatz and related tools. Those credentials can then be used to move laterally toward specific high-value systems and data. 

Operational Capabilities 

Gallium’s operational toolkit combines legitimate Windows functionality, publicly available utilities, modified security tools, tunneling software, credential-stealing utilities, and multiple backdoor families. The group has demonstrated the following capabilities: 

  • Exploitation of Public-Facing Applications – Gallium has exploited publicly accessible servers, including WildFly/JBoss infrastructure, to obtain initial access to victim networks. 
  • Credential Theft and Credential Dumping – The group has used modified versions of Mimikatz, including a PowerShell-based implementation, to dump credentials from compromised machines. It has also used reg commands to extract specific Windows Registry hives, including the SAM hive, to obtain password hashes. 
  • Persistence Through Accounts and Services – Gallium has leveraged valid accounts, created high-privileged domain accounts, used VPN services such as SoftEther VPN, established web shells, and created scheduled tasks to maintain access. 
  • Lateral Movement – The group has used WMI, PsExec, pass-the-hash, and other remote execution techniques to move between systems and deploy tools across multiple assets. 
  • Network Discovery – Gallium has used ipconfig /all, modified NBTscan, ping, whoami, query user, and netstat -oan to understand network configuration, identify remote systems, determine logged-in users, and enumerate active network connections. 
  • Defense Evasion – The group has modified HTRAN, obfuscated strings, packed payloads using both known and custom packers, renamed legitimate utilities such as cmd.exe, and used stolen certificates to sign tools. 
  • Tunneling and Remote Access – HTran and SoftEther VPN have been used to provide tunneling capabilities and maintain access to compromised environments. 
  • Collection and Exfiltration – Gallium has collected information from local systems, including password hashes stored in the Windows SAM Registry hive, while some of its associated malware families provide broader information-stealing and exfiltration capabilities. 

Malware and Tooling 

Gallium has been associated with 25 malware and tool families, reflecting a toolkit that mixes commodity software, legitimate administrative utilities, credential-stealing tools, tunneling software, and purpose-built backdoors. 

Known tooling includes: 

  • at – Tools 
  • cmd – Tools 
  • HTran – Tunneling 
  • ipconfig – Tools 
  • LaZagne – Credential stealer 
  • Mimikatz – Credential stealer, Keylogger 
  • nbtscan – Tools 
  • Net – Tools 
  • netcat – Reconnaissance, Backdoor, Exfiltration 
  • Ping – Tools 
  • PsExec – Remote command 
  • QuasarRAT – Tools 
  • Reg – Tools 
  • SoftEther VPN – Tunneling 
  • Windows Credentials Editor – Credential stealer 
  • WinRAR – Compression 
  • BlackMould – Backdoor 
  • China Chopper – Malware 
  • Gh0stCringe RAT – Backdoor 
  • PingPull – Backdoor 
  • PlugX – Reconnaissance, Backdoor, Keylogger, Information Stealer, Exfiltration 
  • Poison Ivy – Malware 
  • QuarkBandit – Backdoor, Keylogger, Information Stealer 
  • Reshell – Backdoor 
  • Sword2033 – Backdoor, Downloader, Exfiltration 

The breadth of this toolkit is notable because Gallium does not depend on one distinctive malware family. Instead, the group can combine interchangeable utilities and malware according to the requirements of an individual intrusion. 

Attack Methodology 

Gallium’s attack methodology is centered on obtaining an initial foothold through exposed infrastructure and then turning that foothold into persistent access across the victim network. 

The attack can begin with scanning for publicly accessible services. Once a vulnerable WildFly/JBoss server is identified, Gallium can exploit the exposed application to obtain access. After initial compromise, the group may deploy tools and establish persistence through scheduled tasks, high-privileged accounts, VPN access, web shells, or other mechanisms. 

Credential theft then becomes an important component of the operation. Modified Mimikatz implementations and PowerShell can be used to obtain credentials from compromised machines, while Registry commands can retrieve password hashes from the SAM hive. 

The group can subsequently use those credentials through pass-the-hash to authenticate to additional systems. WMI and PsExec support remote execution and lateral movement, allowing Gallium to deploy tools across multiple hosts. 

During this stage, network discovery utilities help determine the structure of the victim environment. ipconfig /all provides network configuration information, modified NBTscan identifies available NetBIOS name servers, ping identifies remote systems, whoami and query user provide information about users, and netstat -oan exposes active network connections. 

Gallium can also employ tunneling infrastructure, including HTran and SoftEther VPN, to maintain communications or remote access. Its infrastructure strategy is relatively inexpensive and replaceable, relying on dynamic-DNS domains and reused hop points rather than maintaining a highly specialized infrastructure footprint. 

The group’s use of common malware and publicly available tools, often with relatively minor modifications, suggests an operational philosophy centered on practicality and adaptability rather than unnecessary complexity. 

Defense Evasion and Persistence 

Gallium has demonstrated several techniques intended to reduce the visibility of its activity. 

The group has used a modified version of HTRAN in which strings such as debug messages were obfuscated, apparently to make the tool more difficult to detect. It has also packed payloads using different types of packers, including both known and custom implementations. 

Gallium has sought to ensure that individual payloads have unique hashes, including through the use of different packing techniques. It has also renamed legitimate utilities, including a renamed cmd.exe, to complicate detection based on expected filenames. 

Another notable technique is the use of stolen code-signing certificates. Gallium has used stolen certificates to sign tools, including certificates associated with Whizzimo LLC, potentially giving malicious tooling a more legitimate appearance. 

For persistence, Gallium has used valid accounts, created high-privileged domain users, established scheduled tasks for Poison Ivy, deployed web shells, and used VPN services including SoftEther VPN. It has also used DLL side-loading to covertly load Poison Ivy into memory on victim machines. 

MITRE ATT&CK Techniques Mapped to Gallium

Gallium’s known ATT&CK activity spans initial access, execution, persistence, defense evasion, credential access, discovery, lateral movement, and collection. 

  • Initial Access – Exploit Public-Facing Application (T1190): Gallium exploited publicly facing servers, including WildFly/JBoss servers, to gain access to victim networks. 
  • Execution – Windows Management Instrumentation (T1047): The group used WMI for execution, assisting both lateral movement and the installation of tools across multiple assets. 
  • Execution – Scheduled Task/Job: Scheduled Task (T1053.005): Gallium created a scheduled task to establish persistence for Poison Ivy. 
  • Execution – PowerShell (T1059.001): PowerShell was used for execution, lateral movement, and credential dumping from compromised systems. 
  • Execution – Windows Command Shell (T1059.003): Gallium used the Windows command shell to execute commands. 
  • Persistence – Valid Accounts (T1078): The group leveraged valid accounts to retain access to victim networks. 
  • Persistence – External Remote Services (T1133): Gallium used VPN services, including SoftEther VPN, to access and maintain persistence in compromised environments. 
  • Persistence – Create Account: Domain Account (T1136.002): The group created high-privileged domain accounts to maintain access. 
  • Persistence – Server Software Component: Web Shell (T1505.003): Web shells were used to persist within victim environments and support execution and exfiltration. 
  • Persistence – Hijack Execution Flow: DLL Side-Loading (T1574.001): Gallium used DLL side-loading to covertly load Poison Ivy into memory. 
  • Defense Evasion – Obfuscated Files or Information (T1027): A modified HTRAN implementation was used with obfuscated strings, including debug messages, in an apparent effort to evade detection. 
  • Defense Evasion – Software Packing (T1027.002): Payloads were packed using multiple types of packers, including known and custom packers. 
  • Defense Evasion – Indicator Removal from Tools (T1027.005): Gallium sought to give payloads unique hashes through the use of different packers. 
  • Defense Evasion – Masquerading: Rename System Utilities (T1036.003): The group used a renamed cmd.exe to evade detection. 
  • Defense Evasion – Subvert Trust Controls: Code Signing (T1553.002): Gallium used stolen certificates to sign tools, including certificates associated with Whizzimo LLC. 
  • Credential Access – OS Credential Dumping: LSASS Memory (T1003.001): Modified Mimikatz and a PowerShell-based Mimikatz were used to dump credentials from victim machines. 

Conclusion 

Gallium remains a persistent threat to telecommunications, government, law enforcement, and financial organizations. Its use of vulnerable internet-facing services, credential theft, lateral movement, and evasive tooling can make detection difficult.

Organizations should prioritize patching exposed applications, securing privileged accounts, and monitoring for suspicious remote-access and lateral-movement activity. Tracking Gallium’s tactics, infrastructure, and malware can help security teams detect and respond to potential intrusions earlier.

See Gallium activity before it reaches your network. Explore how Cyble’s cyber threat intelligence solution can help security teams monitor threat actors, infrastructure, malware, and emerging indicators with actionable threat intelligence. Request a personalized demo today to see the platform in action. 

Frequently Asked Questions 

What is Gallium? 

Gallium is a China-associated advanced persistent threat group known for targeted intrusions, particularly against telecommunications providers. It is tracked by MITRE ATT&CK as G0093 and is also known as Alloy Taurus, Granite Typhoon, Operation Soft Cell, and Phantom Panda. 

When was Gallium active? 

Gallium has been primarily active from 2018 to mid-2019. Its profile currently lists the group as last seen on August 24, 2026. 

Which sectors does Gallium target? 

Known target industries include telecommunications, government and law enforcement, and BFSI. 

How does Gallium gain initial access? 

The group has exploited publicly facing applications, particularly vulnerable WildFly/JBoss servers, to obtain initial access to victim networks. 

How does Gallium maintain persistence? 

Gallium has used valid accounts, high-privileged domain accounts, VPN services such as SoftEther VPN, web shells, scheduled tasks, and DLL side-loading to maintain access. 

What tools does Gallium use for credential theft? 

Known credential-access tooling includes Mimikatz, LaZagne, and Windows Credentials Editor. The group has also used Registry commands to extract SAM data and password hashes. 

How does Gallium move laterally? 

The group has used pass-the-hash, WMI, PsExec, and other remote execution mechanisms to move between systems and deploy tools across victim environments. 

How does Gallium evade detection? 

Its techniques include modified and obfuscated HTRAN components, software packing, unique payload hashes, renamed utilities, DLL side-loading, and the use of stolen code-signing certificates. 

What malware is associated with Gallium? 

Its known toolkit includes Poison Ivy, PlugX, Gh0stCringe RAT, PingPull, China Chopper, BlackMould, QuarkBandit, Reshell, Sword2033, QuasarRAT, and other malware and utility families, for a reported total of 25 families and tools. 

What should organizations prioritize when defending against Gallium? 

Organizations should prioritize patching and monitoring internet-facing applications, especially WildFly/JBoss deployments; protecting privileged accounts; monitoring PowerShell, WMI, PsExec, and pass-the-hash activity; detecting anomalous VPN and web-shell usage; and investigating suspicious signed or packed binaries. 

Media Disclaimer: This profile is compiled from the supplied threat-intelligence information and associated MITRE ATT&CK technique descriptions. It is intended for cybersecurity research, threat-awareness, detection engineering, and defensive planning. Organizations should independently validate indicators, infrastructure, dates, and attribution before using the information for operational decisions. 

Discover how we help proactively defend against evolving threats with Gen 3 intelligence. Request a Demo today!

Share Post:

Stay Informed

The Cyber Briefing Security Teams Actually Read!

Join security teams across 50+ countries getting Cyble's weekly research, advisories, and analyst insights.

No spam, ever. Unsubscribe anytime.

Related Topics

Scroll to Top

Book your session

Request a Personalized Demo

See how Cyble's threat intelligence protects your organization. A specialist will reach out within one business day.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams

Download the brochure

Get the Cyble Vision Brochure

Explore how Cyble Vision delivers AI-powered threat intelligence across your attack surface. Fill in your details to access the brochure.

Select one or more options

Cyble protects your personal data to manage your account and deliver requested content. Submit your details to receive updates. Withdraw consent anytime. See our privacy policy for details.

Your information is encrypted and never shared.
SOC 2 Type II GDPR compliant Trusted by 1,000+ teams