Menu
Browse

Cyber Threat Actor: GALLIUM

Aliases: 3 aliases
Actor Type Location Known Incidents
 Icon
Nation State
China
4 incidents
Profile

GALLIUM, also tracked as Softcell and UNC2814, is a threat actor publicly linked to China and recognized by Belgian authorities as a Chinese state‑backed advanced persistent threat group. The actor operates under multiple aliases that appear together in official statements, indicating a single entity referred to interchangeably as GALLIUM, Softcell, or UNC2814. Attribution to a Chinese nexus comes from the Belgian government’s July 2022 assessment that identified the group alongside APT27, APT30, and APT31 as responsible for cyberespionage against Belgian federal institutions. Chinese officials denied the allegations, but the public record treats the actor as a state‑sponsored entity based on the governmental attribution.

The actor’s known targeting focuses on government and telecommunications sectors in Western Europe. In the Belgian case, the group was said to have compromised the Federal Public Service Interior and the Belgian Defence ministries, aiming to affect sovereignty, democracy, security and societal integrity. A separate incident involving Austria’s largest ISP, A1 Telekom, was described by a whistleblower as a breach by a Chinese state‑linked group that sought to map internal systems and potentially extract customer data, although the victim did not confirm the attribution. These incidents show a pattern of espionage‑oriented intrusions rather than financially motivated crime or destructive disruption. No public source attributes financial gain or sabotage objectives to GALLIUM/Softcell/UNC2814.

Reported tactics include the deployment of malware to gain an initial foothold, followed by manual expansion within the victim network. After intrusion, the actors executed database queries to map internal systems, a technique observed during the A1 Telekom incident where they reportedly explored the network over a prolonged period. The Belgian statements do not specify particular malware families or exploit kits, but they note that the activity was detected as malicious cyber operations targeting ministries. Remediation efforts in the Austrian case involved password resets for all employees and servers after the attackers were expelled, indicating that credential access was part of the post‑exploitation phase. No details about specific tooling, command‑and‑control infrastructure, or zero‑day exploits are provided in the available sources.

The most cited operations involving GALLIUM/Softcell/UNC2814 are the July 2022 cyberespionage campaign against Belgian defense and interior ministries and the November 2019 breach of A1 Telekom in Austria. The Belgian intrusion was characterized as a sustained effort that compromised sovereignty‑related institutions and prompted a diplomatic call for China to curb malicious cyber activity originating from its territory. The Austrian breach, while not officially confirmed by the ISP as state‑led, was described by a whistleblower as a Chinese‑linked effort to gather telecom‑related information and led to a months‑long remediation process. These two publicly reported episodes constitute the primary evidence of the actor’s operational focus and behavior.

Incidents
Attributed incidents available to members
4 incidents
Sources
Sources available to members
1 source