Home/Threat Actor/GALLIUM
Threat Actor

GALLIUM

gallium · china · active since 2012

GALLIUM (Operation Soft Cell / Granite Typhoon / Alloy Taurus / BRONZE ATLAS / G0093) is a Chinese state-sponsored cyber- espionage actor active since at least 2012 with a defining mission specialization: sustained compromise of global telecommunications providers for bulk Call Detail Record, subscriber-metadata, and communications-content collection supporting PRC dissident-tracking, diplomatic-collection, and economic-intelligence objectives.

public-attribution baseline established by the June 25, 2019 Cybereason 'Operation Soft Cell' and December 12, 2019 Microsoft 'GALLIUM: Targeting Global Telecom' disclosures documenting multi-wave compromise of at least 10 major telecommunications providers globally with full network takeovers and attacker-created domain admin accounts.

targeting spans Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam, with subsequent expansion across Southeast Asia, the Middle East, Africa, and Europe and sectoral expansion to government and financial-services targets (Palo Alto Unit 42 June 2022)

technically distinguished by initial access via unpatched internet-facing services (WildFly/JBoss early, Exchange ProxyLogon/ProxyShell, Log4Shell), China Chopper web-shell persistence, modified Soft Cell Mimikatz variants with distinctive PDB paths sharing lineage with the 2023 SentinelLABS Operation Tainted Love mim221 capability, the PingPull custom backdoor with signature ICMP-tunneling C2 (Unit 42 June 2022), PoisonIvy / gh0st RAT / HTran / Quarian / HighTide implant family, heavy DLL side-loading via legitimately-signed binaries, and use of Taiwan-based servers exclusive to GALLIUM as an infrastructure-attribution pillar; the broader Chinese-state telecom-collection mission spans multiple coordinated clusters including GALLIUM, Salt Typhoon (whose 2024 disclosure of broad US-telecom CALEA-related-systems compromise raised questions about operational overlap), Volt Typhoon, and APT41 sub-clusters tracked separately.

china confidence: high 16 aliases MITRE ATT&CK G0093 ↗

Profile

GALLIUM (Operation Soft Cell / Granite Typhoon / Alloy Taurus / Operation Tainted Love overlap / BRONZE ATLAS overlap / G0093) is a Chinese state-sponsored cyber-espionage actor active since at least 2012 with a defining mission specialization: sustained compromise of global telecommunications providers for bulk Call Detail Record (CDR), subscriber-metadata, and communications- content collection. Public attribution rests on tooling and TTP overlap with broader Chinese state-actor patterns (notably APT10 / Stone Panda and APT41 / Wicked Panda), exclusive use of Taiwan-based command-and-control infrastructure, and targeting consistent with PRC strategic-intelligence priorities. Specific PRC unit affiliation has not been publicly named, GALLIUM's precise organizational placement within China's MSS provincial bureau system versus broader contractor ecosystem remains a gap in open-source attribution. The June 25, 2019 Cybereason Operation Soft Cell disclosure and the December 12, 2019 Microsoft GALLIUM disclosure together established the public-attribution baseline, documenting multi-wave compromise of at least 10 major telecommunications providers globally with full network takeovers including attacker-created domain admin accounts. The pattern was sustained CDR collection on specific high-value subscriber targets, supporting PRC dissident-tracking, diplomatic- collection, and economic-intelligence objectives. Targeted regions span at minimum Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam, with subsequent expansion to wider Southeast Asia, the Middle East, Africa, and Europe. Tradecraft is characteristic of the broader Chinese-state ecosystem with several distinguishing features: (a) initial access via unpatched internet-facing services, particularly WildFly / JBoss application servers in early operations, then heavy Microsoft Exchange exploitation (ProxyLogon and ProxyShell chains), Log4Shell, and a sustained pattern of n-day exploitation rather than zero-day development; (b) China Chopper web-shell deployment as the persistent foothold pattern.

(c) modified Soft Cell Mimikatz variants with distinctive PDB paths (the 2023 SentinelLABS Operation Tainted Love disclosure identified the mim221 versioned credential-theft capability sharing PDB-path lineage with the Operation Soft Cell Mimikatz)

(d) the PingPull custom backdoor with signature ICMP-tunneling C2 (Unit 42 June 2022), ICMP tunneling exploits the gap that few enterprises deep-inspect ICMP traffic.

(e) PoisonIvy, gh0st RAT, HTran proxying tools, Quarian, and HighTide as the broader implant family.

(f) heavy DLL side-loading via legitimately-signed binaries (the broader Chinese state-actor pattern)

(g) sustained operational tempo across more than a decade with continuous tooling-development investment. The September 2024 disclosure of Salt Typhoon's broad compromise of US telecommunications providers (including CALEA-related systems for lawful-intercept access) raised questions about operational overlap with the historical GALLIUM / Soft Cell mission set.

Microsoft tracks Salt Typhoon as a separate cluster but the broader Chinese-state telecom- collection mission spans multiple coordinated clusters including GALLIUM, Salt Typhoon, Volt Typhoon, and APT41 sub-clusters.

Aliases

16
galliumoperation soft celloperation softcellsoft cellsoftcellgranite typhoonbronze atlasbronze_atlasalloy taurusalloy_taurusoperation tainted loveoperation_tainted_lovemssministry of state securitychina state securityg0093

Notable Campaigns

8
2024-2026Sustained Telecom Sector Collection (2024-2026)
2024Salt Typhoon US Telecom Compromise Adjacent Activity (2024)
2023Microsoft Granite Typhoon Renaming (2023)
2023Operation Tainted Love (SentinelLABS / QGroup March 2023)
2022PingPull Backdoor and Sectoral Expansion (Palo Alto Unit 42 June 13, 2022)
2019Operation Soft Cell Public Disclosure (Cybereason June 25, 2019)
2019Microsoft GALLIUM, Targeting Global Telecom (December 12, 2019)
2012-2018Early Telecom Operations (2012-2018)

Attribution & Reporting

Attributed by
FBICISANSAUK NCSCFive EyesMicrosoftMandiantGoogle Cloud Threat IntelligenceCrowdStrikeCybereasonCybereason NocturnusPalo Alto Networks Unit 42SentinelOneSentinelLABSQGroupSymantec / BroadcomTrend MicroCisco TalosRecorded FutureInsikt GroupSecureWorksESETKasperskyCheck Point ResearchMandiant Threat IntelligenceIndustrial CyberAttackIQ
Key reporting
reportCybereason Nocturnus: Operation Soft Cell, A Worldwide Campaign Against Telecommunications Providers (June 25, 2019)
reportMicrosoft Threat Intelligence Center: GALLIUM, Targeting Global Telecom (December 12, 2019)
reportPalo Alto Networks Unit 42: GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool (June 13, 2022)
reportPalo Alto Networks Unit 42: Alloy Taurus Atom Page
reportSentinelLABS + QGroup: Operation Tainted Love, Chinese APTs Target Telcos in New Attacks (March 2023)
reportSentinelLABS: Lifting the Soft Cell Cluster
reportAttackIQ: Emulating the Highly Elusive Chinese Adversary Gallium (July 2023)
reportCybereason: Using MITRE ATT&CK to Identify Advanced Threats, Operation Soft Cell Webinar
reportIndustrial Cyber: GALLIUM APT Group Uses PingPull Malware (2022)
reportRecorded Future / Insikt Group: Chinese State-Sponsored Targeting of Telecom
reportCrowdStrike: Adversary Profile, BRONZE ATLAS
reportSecureWorks: BRONZE ATLAS Threat Group Profile
reportMandiant: Southeast Asia, An Evolving Cyber Threat Landscape
reportCouncil on Foreign Relations: GALLIUM Cyber Operations Tracker
reportEuRepoC: APT Profile, GALLIUM

Operational

State sponsor

People's Republic of China (PRC), assessed by Microsoft, Cybereason, Palo Alto Networks Unit 42, SentinelOne, and others as a likely Chinese state-sponsored group based on tooling, TTPs, infrastructure overlap with other Chinese-attributed clusters (notably APT10 / Stone Panda, APT41), use of Taiwan-based servers exclusive to GALLIUM, and targeting aligned with PRC strategic-intelligence priorities. Microsoft taxonomy places the cluster as Granite Typhoon. Specific PRC government affiliation (MSS provincial unit vs. broader contractor ecosystem) not publicly attributed to a named entity.

Motivations
espionage, intelligence_gathering, telecommunications_surveillance, call_detail_record_collection, communications_metadata_collection, subscriber_data_collection, dissident_tracking, diplomatic_intelligence, economic_intelligence, government_intelligence, regional_dominance, chinese_diaspora_surveillance
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)56/60 · 93%
Analytics (MITRE CAR)36/60 · 60%
Runtime / container (Falco)5/60 · 8%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)13/60 · 21%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

13 mapped
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin