GALLIUM

G0093

Threat group.View on attack.mitre.org

About this group

GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers. Security researchers have identified GALLIUM as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.

Techniques used31

Procedure examples31

TechniqueProcedure example
T1003.001
LSASS Memory

GALLIUM used a modified version of Mimikatz along with a PowerShell-based Mimikatz to dump credentials on the victim machines.

T1003.002
Security Account Manager

GALLIUM used reg commands to dump specific hives from the Windows Registry, such as the SAM hive, and obtain password hashes.

T1005
Data from Local System

GALLIUM collected data from the victim's local system, including password hashes from the SAM hive in the Registry.

T1016
System Network Configuration Discovery

GALLIUM used ipconfig /all to obtain information about the victim network configuration. The group also ran a modified version of NBTscan to identify available NetBIOS name servers.

T1018
Remote System Discovery

GALLIUM used a modified version of NBTscan to identify available NetBIOS name servers over the network as well as ping to identify remote systems.

T1027
Obfuscated Files or Information

GALLIUM used a modified version of HTRAN in which they obfuscated strings such as debug messages in an apparent attempt to evade detection.

T1027.002
Software Packing

GALLIUM packed some payloads using different types of packers, both known and custom.

T1027.005
Indicator Removal from Tools

GALLIUM ensured each payload had a unique hash, including by using different types of packers.

T1033
System Owner/User Discovery

GALLIUM used whoami and query user to obtain information about the victim user.

T1036.003
Rename Legitimate Utilities

GALLIUM used a renamed cmd.exe file to evade detection.

T1041
Exfiltration Over C2 Channel

GALLIUM used Web shells and HTRAN for C2 and to exfiltrate data.

T1047
Windows Management Instrumentation

GALLIUM used WMI for execution to assist in lateral movement as well as for installing tools across multiple assets.

T1049
System Network Connections Discovery

GALLIUM used netstat -oan to obtain information about the victim network connections.

T1053.005
Scheduled Task

GALLIUM established persistence for PoisonIvy by created a scheduled task.

T1059.001
PowerShell

GALLIUM used PowerShell for execution to assist in lateral movement as well as for dumping credentials stored on compromised machines.

View all 31 procedure examples

Software16

Campaigns0

None recorded.

References3

  1. Cybereason Soft Cell June 2019 Open source
    Cybereason Nocturnus. (2019, June 25). Operation Soft Cell: A Worldwide Campaign Against Telecommunications Providers. Retrieved July 18, 2019.
  2. Microsoft GALLIUM December 2019 Open source
    MSTIC. (2019, December 12). GALLIUM: Targeting global telecom. Retrieved January 13, 2021.
  3. Unit 42 PingPull Jun 2022 Open source
    Unit 42. (2022, June 13). GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool. Retrieved August 7, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.