CSIDB logo
Threat actor

GALLIUM

Attribution profile

Type
Nation State
Location
China
Known incidents
4 incidents
Sources
1 source
First seen
2019-11-01
Last seen
2022-07-19
Updated
2026-08-01 04:14
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

GALLIUM, also tracked as Softcell and UNC2814, is a threat actor identified by Belgian authorities as part of a set of Chinese state‑backed advanced persistent threat groups that includes APT27, APT30 and APT31. The actor’s location is noted as China, and its activities have been publicly attributed to a Chinese state nexus by government statements and whistleblower accounts. Its primary objective, as evidenced by the incidents described, is cyberespionage aimed at gathering sensitive information from governmental and telecommunications targets. The actor has been observed targeting national defense and interior ministries, as well as a major telecommunications provider, indicating a focus on sectors that hold strategic or intelligence‑value data. No public reporting links the group to financially motivated crime or disruptive operations, and the sources describe its actions solely in terms of espionage‑oriented intrusions.

In the Belgian incidents of July 2022, GALLIUM/Softcell/UNC2814 was said to have conducted malicious cyber activities against the Federal Public Service Interior and the Belgian Defence, actions that were characterized as compromising sovereignty, democracy and security. The Austrian telecom breach reported in November 2019 involved a malware infection that allowed attackers to manually expand access within A1 Telekom’s network, query databases to map internal systems and, according to a whistleblower, extract certain customer details before being expelled and prompting a forced password reset across the environment. These examples illustrate the actor’s use of custom or unspecified malware to gain initial footholds, followed by manual network exploration and data collection techniques. No additional malware families, specific tools or initial‑access vectors are detailed in the provided material, so the profile is limited to the observed patterns of espionage‑focused intrusion, manual lateral movement and database interrogation. The attribution to a Chinese state‑linked group rests on the Belgian government’s public statements and the whistleblower’s assertion, with no alternative criminal or non‑state affiliation indicated in the sources.

Incidents

Attributed incidents are available to members.

4 incidents

Sources

Sources available to members: 1 source.

CSIDB