Threat group.View on attack.mitre.org
GALLIUM is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers. Security researchers have identified GALLIUM as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
GALLIUM used a modified version of Mimikatz along with a PowerShell-based Mimikatz to dump credentials on the victim machines. |
| T1003.002 Security Account Manager |
GALLIUM used |
| T1005 Data from Local System |
GALLIUM collected data from the victim's local system, including password hashes from the SAM hive in the Registry. |
| T1016 System Network Configuration Discovery |
GALLIUM used |
| T1018 Remote System Discovery |
GALLIUM used a modified version of NBTscan to identify available NetBIOS name servers over the network as well as |
| T1027 Obfuscated Files or Information |
GALLIUM used a modified version of HTRAN in which they obfuscated strings such as debug messages in an apparent attempt to evade detection. |
| T1027.002 Software Packing |
GALLIUM packed some payloads using different types of packers, both known and custom. |
| T1027.005 Indicator Removal from Tools |
GALLIUM ensured each payload had a unique hash, including by using different types of packers. |
| T1033 System Owner/User Discovery |
GALLIUM used |
| T1036.003 Rename Legitimate Utilities |
GALLIUM used a renamed cmd.exe file to evade detection. |
| T1041 Exfiltration Over C2 Channel |
GALLIUM used Web shells and HTRAN for C2 and to exfiltrate data. |
| T1047 Windows Management Instrumentation |
GALLIUM used WMI for execution to assist in lateral movement as well as for installing tools across multiple assets. |
| T1049 System Network Connections Discovery |
GALLIUM used |
| T1053.005 Scheduled Task |
GALLIUM established persistence for PoisonIvy by created a scheduled task. |
| T1059.001 PowerShell |
GALLIUM used PowerShell for execution to assist in lateral movement as well as for dumping credentials stored on compromised machines. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.