PULSE NAME
GALLIUM Expands Targeting Across Telecommunications, Government and Finance Sectors With New PingPull Tool
WHITE AlienVault 2022-06-13 Modified: 2022-07-13
17
IOCs
MEDIUM VOLUME
Unit 42 recently identified a new, difficult-to-detect remote access trojan named PingPull being used by GALLIUM, an advanced persistent threat (APT) group. Unit 42 actively monitors infrastructure associated with several APT groups. One group in particular, GALLIUM (also known as Softcell), established its reputation by targeting telecommunications companies operating in Southeast Asia, Europe and Africa. The group’s geographic targeting, sector-specific focus and technical proficiency, combined with their use of known Chinese threat actor malware and tactics, techniques and procedures (TTPs), has resulted in industry assessments that GALLIUM is likely a Chinese state-sponsored group.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
PingPull
Indicators of Compromise (17)
All FileHash-SHA1 FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 76efd8ef3f64059820d937fa87acf9369775ecd5 2022-06-13
FileHash-SHA256 1ce1eb64679689860a1eacb76def7c3e193504be53ebb0588cddcbde9d2b9fe6 2022-06-13
FileHash-SHA256 8b664300fff1238d6c741ac17294d714098c5653c3ef992907fc498655ff7c20 2022-06-13
FileHash-SHA256 b4aabfb8f0327370ce80970c357b84782eaf0aabfc70f5e7340746f25252d541 2022-06-13
FileHash-SHA256 c55ab8fdd060fb532c599ee6647d1d7b52a013e4d8d3223b361db86c1f43e845 2022-06-13
FileHash-SHA256 de14f22c88e552b61c62ab28d27a617fb8c0737350ca7c631de5680850282761 2022-06-13
FileHash-SHA256 f86ebeb6b3c7f12ae98fe278df707d9ebdc17b19be0c773309f9af599243d0a3 2022-06-13
FileHash-SHA256 fc2147ddd8613f08dd833b6966891de9e5309587a61e4b35408d56f43e72697e 2022-06-13
domain hinitial.com 2022-06-13
domain micfkbeljacob.com 2022-06-13
hostname df.micfkbeljacob.com 2022-06-13
hostname jack.micfkbeljacob.com 2022-06-13
hostname t1.hinitial.com 2022-06-13
hostname v2.hinitial.com 2022-06-13
hostname v3.hinitial.com 2022-06-13
hostname v4.hinitial.com 2022-06-13
hostname v5.hinitial.com 2022-06-13