GALLIUM

THREAT ACTOR PROFILE

GALLIUM

GALLIUM

GALLIUM

Alloy Taurus

GALLIUM is a China-nexus espionage group active since at least 2017, known for Operation Soft Cell against telecommunications providers and for targeting government entities across the Middle East, Southeast Asia and beyond. In 2026 Google and Mandiant disrupted its GRIDTIDE campaign, which abused Google Sheets API calls for covert command-and-control.

China

Telecom / Government

First seen

2017

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

GALLIUM, Alloy Taurus and Granite Typhoon

GALLIUM is tracked under several vendor names. It maps to one entry among the PRC-nexus actors we profile, and its China-nexus espionage overlaps with crews like APT41.

-

-

-

GROUP PROFILE

Telecom-focused espionage with cloud-based C2

GALLIUM is a China-nexus espionage actor with a long record against telecommunications operators, where access yields call records and subscriber data useful for intelligence. It has also hit government targets, exploiting public-facing servers for entry.

Our record places its origin as China and ties it to espionage across telecom and government sectors. Google Threat Intelligence Group and Mandiant disrupted a long-running global espionage campaign by UNC2814 using the GRIDTIDE backdoor.

The group historically exploited Exchange servers to deploy web shells, and in its recent activity adopted GRIDTIDE, a C-based backdoor that blends C2 traffic into legitimate Google Sheets API calls.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

-

ATTACK LIFECYCLE

Server exploitation into GRIDTIDE

The stages below come from GALLIUM and Alloy Taurus activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

GRIDTIDE, mim221 and web shells

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

CVES EXPLOITED

Public-facing server exploitation without a fixed CVE set

GALLIUM's intrusions in our records rely on exploiting public-facing servers, including Microsoft Exchange, to drop web shells, but our records do not tie the group to a specific, confirmed set of exploited CVEs. Detection should focus on web-shell activity on internet-facing servers and on GRIDTIDE's Google Sheets-based C2.

GALLIUM

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

GALLIUM

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

GALLIUM

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

GALLIUM

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

GRIDTIDE and Operation Tainted Love

Reporting tracks the group's cloud-based backdoor and telecom targeting.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

GALLIUM

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

GALLIUM

IOC set, full IP, host and hash history.