Threat actor · all actors
GALLIUMG0093 state
🇨🇳 CN
aka GALLIUM, Granite Typhoon, Red Dev 4, Alloy Taurus, PHANTOM PANDA
Last updated: 2026-08-20
About this actor
[GALLIUM](https://attack.mitre.org/groups/G0093) is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers.(Citation: Cybereason Soft Cell June 2019) Security researchers have identified [GALLIUM](https://attack.mitre.org/groups/G0093) as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.(Citation: Cybereason Soft Cell June 2019)(Citation: Microsoft GALLIUM December 2019)(Citation: Unit 42 PingPull Jun 2022)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
Palo Alto Unit 42constellation names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 45 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1003.002Security Account Manager ↗T1005Data from Local System ↗T1016System Network Configuration Discovery ↗T1018Remote System Discovery ↗T1027Obfuscated Files or Information ↗T1027.002Software Packing ↗T1027.005Indicator Removal from Tools ↗T1033System Owner/User Discovery ↗T1036Masquerading ↗T1036.003Rename Legitimate Utilities ↗T1041Exfiltration Over C2 Channel ↗T1047Windows Management Instrumentation ↗T1049System Network Connections Discovery ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1078Valid Accounts ↗T1090Proxy ↗T1090.002External Proxy ↗T1105Ingress Tool Transfer ↗T1133External Remote Services ↗T1136Create Account ↗T1136.002Domain Account ↗T1190Exploit Public-Facing Application ↗T1505Server Software Component ↗T1505.003Web Shell ↗T1550Use Alternate Authentication Material ↗T1550.002Pass the Hash ↗T1553Subvert Trust Controls ↗T1553.002Code Signing ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1570Lateral Tool Transfer ↗T1574Hijack Execution Flow ↗T1574.001DLL ↗T1583Acquire Infrastructure ↗T1583.004Server ↗T1588Obtain Capabilities ↗T1588.002Tool ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 31 / 45 | 69% |
CM-6 | 28 / 45 | 62% |
AC-3 | 27 / 45 | 60% |
AC-6 | 24 / 45 | 53% |
CM-2 | 24 / 45 | 53% |
AC-2 | 23 / 45 | 51% |
SI-3 | 22 / 45 | 49% |
CM-7 | 21 / 45 | 47% |
AC-5 | 17 / 45 | 38% |
CM-5 | 17 / 45 | 38% |
IA-2 | 17 / 45 | 38% |
SI-7 | 16 / 45 | 36% |
CA-7 | 14 / 45 | 31% |
RA-5 | 14 / 45 | 31% |
AC-4 | 12 / 45 | 27% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- C0017 0.39
- menuPass 0.39
- FIN13 0.35
- Operation CuckooBees 0.35
- SharePoint ToolShell Exploitation 0.34
Same nation-state
- Night Dragon 1.00
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00