GALLIUM

APT / StateG0093
Origin🇨🇳 China
Techniques (MITRE ATT&CK)31
SourceMITRE ATT&CK
0
Also known as:Granite Typhoon

Vexday analysis

Grupo de ciberespionagem de origem chinesa, ativo desde pelo menos 2012, o GALLIUM (também rastreado como Granite Typhoon, identificador MITRE ATT&CK G0093) tem como alvos principais empresas de telecomunicações, instituições financeiras e entidades governamentais em países como Afeganistão, Austrália, Bélgica, Camboja, Malásia, Moçambique, Filipinas, Rússia e Vietnã. O grupo é especialmente associado à Operação Soft Cell, uma campanha de longa duração direcionada a provedores de telecomunicações. Pesquisadores de segurança o classificam como um provável grupo patrocinado pelo Estado chinês, com base nas ferramentas e nas TTPs empregadas, características comuns a agentes de ameaça desse país. Seu perfil técnico compreende 31 técnicas documentadas no MITRE ATT&CK e 2 CVEs atribuídas ao grupo.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity62
Impact: High
T1190T1047T1133T1003.001T1550.002T1005ENTRYInitial accessExploitPublic-Facing App…EXECExecutionWindows ManagementInstrumentationPERSPersistenceExternal RemoteServicesCREDCredential accessLSASS MemoryLATLateral movementPass the HashCOLLCollectionData from LocalSystemEXFILExfiltrationExfiltration OverC2 Channel

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities 2

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

GALLIUM uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →