ATT&CKReferencesMicrosoft GALLIUM December 2019

Microsoft GALLIUM December 2019

MSTIC. (2019, December 12). GALLIUM: Targeting global telecom. Retrieved January 13, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples17

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupGALLIUM

GALLIUM used a modified version of Mimikatz along with a PowerShell-based Mimikatz to dump credentials on the victim machines.

T1005
Data from Local System
MalwareBlackMould

BlackMould can copy files on a compromised host.

T1059.003
Windows Command Shell
MalwareBlackMould

BlackMould can run cmd.exe with parameters.

T1071.001
Web Protocols
MalwareBlackMould

BlackMould can send commands to C2 in the body of HTTP POST requests.

T1083
File and Directory Discovery
MalwareBlackMould

BlackMould has the ability to find files on the targeted system.

T1105
Ingress Tool Transfer
GroupGALLIUM

GALLIUM dropped additional tools to victims during their operation, including portqry.exe, a renamed cmd.exe file, winrar, and HTRAN.

T1105
Ingress Tool Transfer
MalwareBlackMould

BlackMould has the ability to download files to the victim's machine.

T1133
External Remote Services
GroupGALLIUM

GALLIUM has used VPN services, including SoftEther VPN, to access and maintain persistence in victim environments.

T1136.002
Domain Account
GroupGALLIUM

GALLIUM created high-privileged domain user accounts to maintain access to victim networks.

T1190
Exploit Public-Facing Application
GroupGALLIUM

GALLIUM exploited a publicly-facing servers including Wildfly/JBoss servers to gain access to the network.

T1505.003
Web Shell
GroupGALLIUM

GALLIUM used Web shells to persist in victim environments and assist in execution and exfiltration.

T1553.002
Code Signing
GroupGALLIUM

GALLIUM has used stolen certificates to sign its tools including those from Whizzimo LLC.

T1560.001
Archive via Utility
GroupGALLIUM

GALLIUM used WinRAR to compress and encrypt stolen data prior to exfiltration.

T1570
Lateral Tool Transfer
GroupGALLIUM

GALLIUM has used PsExec to move laterally between hosts in the target network.

T1583.004
Server
GroupGALLIUM

GALLIUM has used Taiwan-based servers that appear to be exclusive to GALLIUM.

T1588.002
Tool
GroupGALLIUM

GALLIUM has used a variety of widely-available tools, which in some cases they modified to add functionality and/or subvert antimalware solutions.

T1680
Local Storage Discovery
MalwareBlackMould

BlackMould can enumerate local drives on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.