GALLIUM
GALLIUM (Operation Soft Cell / Granite Typhoon / Alloy Taurus / BRONZE ATLAS / G0093) is a Chinese state-sponsored cyber- espionage actor active since at least 2012 with a defining mission specialization: sustained compromise of global telecommunications providers for bulk Call Detail Record, subscriber-metadata, and communications-content collection supporting PRC dissident-tracking, diplomatic-collection, and economic-intelligence objectives.
public-attribution baseline established by the June 25, 2019 Cybereason 'Operation Soft Cell' and December 12, 2019 Microsoft 'GALLIUM: Targeting Global Telecom' disclosures documenting multi-wave compromise of at least 10 major telecommunications providers globally with full network takeovers and attacker-created domain admin accounts.
targeting spans Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam, with subsequent expansion across Southeast Asia, the Middle East, Africa, and Europe and sectoral expansion to government and financial-services targets (Palo Alto Unit 42 June 2022)
technically distinguished by initial access via unpatched internet-facing services (WildFly/JBoss early, Exchange ProxyLogon/ProxyShell, Log4Shell), China Chopper web-shell persistence, modified Soft Cell Mimikatz variants with distinctive PDB paths sharing lineage with the 2023 SentinelLABS Operation Tainted Love mim221 capability, the PingPull custom backdoor with signature ICMP-tunneling C2 (Unit 42 June 2022), PoisonIvy / gh0st RAT / HTran / Quarian / HighTide implant family, heavy DLL side-loading via legitimately-signed binaries, and use of Taiwan-based servers exclusive to GALLIUM as an infrastructure-attribution pillar; the broader Chinese-state telecom-collection mission spans multiple coordinated clusters including GALLIUM, Salt Typhoon (whose 2024 disclosure of broad US-telecom CALEA-related-systems compromise raised questions about operational overlap), Volt Typhoon, and APT41 sub-clusters tracked separately.