Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0093
MITRE ATT&CK Group

GALLIUM (G0093)

Granite Typhoon
ShareXLinkedInRedditHN

[GALLIUM](https://attack.mitre.org/groups/G0093) is a cyberespionage group that has been active since at least 2012, primarily targeting telecommunications companies, financial institutions, and government entities in Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, the Philippines, Russia, and Vietnam. This group is particularly known for launching Operation Soft Cell, a long-term campaign targeting telecommunications providers.(Citation: Cybereason Soft Cell June 2019) Security researchers have identified [GALLIUM](https://attack.mitre.org/groups/G0093) as a likely Chinese state-sponsored group, based in part on tools used and TTPs commonly associated with Chinese threat actors.(Citation: Cybereason Soft Cell June 2019)(Citation: Microsoft GALLIUM December 2019)(Citation: Unit 42 PingPull Jun 2022)

▪Techniques used (31)

T1059.003Windows Command ShellT1003.002Security Account ManagerT1078Valid AccountsT1053.005Scheduled TaskT1027Obfuscated Files or InformationT1553.002Code SigningT1041Exfiltration Over C2 ChannelT1005Data from Local SystemT1574.001DLLT1588.002ToolT1047Windows Management InstrumentationT1136.002Domain AccountT1583.004ServerT1133External Remote ServicesT1027.002Software PackingT1505.003Web ShellT1003.001LSASS MemoryT1560.001Archive via UtilityT1059.001PowerShellT1570Lateral Tool TransferT1027.005Indicator Removal from ToolsT1090.002External ProxyT1049System Network Connections DiscoveryT1074.001Local Data StagingT1033System Owner/User DiscoveryT1190Exploit Public-Facing ApplicationT1016System Network Configuration DiscoveryT1105Ingress Tool TransferT1018Remote System DiscoveryT1550.002Pass the HashT1036.003Rename Legitimate Utilities

▪Software used (16)

S0100ipconfigtoolS0097PingtoolS0106cmdtoolS0020China ChoppermalwareS0012PoisonIvymalwareS0110attoolS0013PlugXmalwareS1031PingPullmalwareS0564BlackMouldmalwareS0002MimikatztoolS0039NettoolS0075RegtoolS0029PsExectoolS0040HTRANtoolS0590NBTscantoolS0005Windows Credential Editortool
G0093on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.