CN

Gallium

High ConfidenceHigh Threat

Softcell • Granite Typhoon • GALLIUM

GALLIUM is a Chinese state-sponsored threat actor that has been active since at least 2018, primarily targeting telecommunications providers, financial institutions, and government entities across Southeast Asia, Europe, Africa, and the Middle East. The group is known for exploiting internet-facing services and using publicly available tools alongside custom malware. GALLIUM's operations support Chinese intelligence collection objectives, with particular focus on gaining persistent access to telecommunications infrastructure for surveillance purposes.

Origin: China
Sponsor: MSS (Ministry of State Security)
Active: 2012 - Present
Victims: 100+ organizations
Advanced
Active
EspionageSurveillance
Risk Assessment
79
Composite Risk Score
High Risk
ARCS Compliance80
Escalation Risk78
Grievance Index72
Infrastructure Impact85
History & Evolution

GALLIUM is a Chinese state-sponsored threat actor that has been active since at least 2018, primarily targeting telecommunications providers, financial institutions, and government entities across Southeast Asia, Europe, Africa, and the Middle East. The group is known for exploiting internet-facing services and using publicly available tools alongside custom malware. GALLIUM's operations support Chinese intelligence collection objectives, with particular focus on gaining persistent access to telecommunications infrastructure for surveillance purposes.

Targeting

Target Sectors

TelecommunicationsTechnologyGovernment

Target Regions

GlobalSoutheast AsiaEuropeMiddle EastAfrica
Attribution & Affiliations

Attributed to MSS (Ministry of State Security) (China). Attribution confidence: High.

Intelligence Assessment
High
Threat Level
Moderately
Targeting
Moderately
Adaptability
High
Persistence
Continuous
Op Tempo
Active
Status

Future Outlook

Gallium is expected to continue operations targeting Telecommunications sectors.

Timeline of Key Events
2012
Major

First observed activity of Gallium

2024
Moderate

Continued active operations