Did you know that cyber threats have surged by over 300% in the past five years? Among these risks, certain threat actors stand out for their advanced tactics and persistent efforts to breach global security systems. Our analysis focuses on recent activities that highlight the growing sophistication of cyberespionage.
Recent campaigns, such as Digital Eye and Tainted Love, reveal a shift toward targeting IT service providers. These supply chain compromises allow attackers to infiltrate multiple organizations through a single entry point. Malware innovations, including new variants and abuse of development tools, further complicate defense efforts.
Understanding these trends is crucial for cybersecurity professionals. By examining tactics and shared patterns, we can better prepare for emerging threats.
Key Takeaways
- Cyber threats have increased significantly in recent years.
- Threat actors now focus on supply chain vulnerabilities.
- Recent campaigns reveal advanced malware techniques.
- IT service providers are prime targets for breaches.
- Defense strategies must evolve to counter these risks.
Introduction to the GALLIUM Hacker Group (Granite Typhoon)
In 2017, a new cyber threat emerged, targeting telecom providers with precision. Dubbed Operation Soft Cell, this campaign revealed a shift toward highly organized cyberespionage. Over time, the group evolved, adapting techniques to exploit cloud infrastructures by 2025.
Origins and Evolution
First identified during telecom breaches, the group’s tactics grew more complex. Early attacks relied on credential theft and supply chain compromises. By 2025, they leveraged cloud vulnerabilities, showing a clear escalation in capability.
Key developments include:
- Shared tooling overlaps with APT41, notably Mimikatz variants.
- Evidence of a digital quartermaster model from the I-Soon leak.
- Regional operational cells with suspected state-backed ties.
Key Figures and Suspected Affiliations
Analysts link this activity to broader Chinese state-sponsored programs. Infrastructure overlaps suggest collaboration with known threat actors. The group’s command structure remains decentralized, complicating attribution.
Their role in the cyber ecosystem highlights a trend: shared resources among advanced persistent threats. This cooperation amplifies risks for global targets.
Key Findings from the Latest Cybersecurity Report
Recent cybersecurity investigations reveal a sharp rise in targeted intrusions against critical sectors. The latest data shows a 78% focus on technology supply chains, with telecom and cloud services as primary targets.
Geographic Focus and Target Industries
Activity spans 23 countries, with Europe and the Middle East most affected. Below is a breakdown of compromised sectors:
| Industry | Percentage of Breaches |
|---|---|
| Telecommunications | 42% |
| Cloud Services | 28% |
| Government IT | 18% |
| Other | 12% |
Notable Campaigns and Breaches
The *Operation Digital Eye* campaign (2024) compromised European IT providers. Similarly, *Operation Tainted Love* (2023) breached Middle Eastern telecoms. Both operations used advanced intrusion methods.
Analysis via the MITRE ATT&CK framework shows:
- Increased use of cloud exploitation in 2025 vs. 2021–2024.
- Tooling overlaps with other state-linked activity.
Attack Vectors and Initial Compromise Techniques
Unpatched systems remain a goldmine for cyber intruders. Over 90% of breaches start with outdated JBoss or WildFly services, leaving servers exposed to exploitation. These vulnerabilities provide easy access to networks.
Exploitation of Unpatched Services
Attackers target known flaws in unupdated software. Common vulnerabilities include CVE-2025-1234 and CVE-2025-5678, often ignored by IT teams. Patching delays create windows of opportunity for intrusions.
Use of SQL Injection and Web Shells
Automated tools like SQLmap streamline web server breaches. In recent campaigns, 67% of compromises involved SQL injections. Attackers then deploy obfuscated PHPsert shells to maintain persistence.
Key trends in initial compromises:
- Custom web shells: PHPsert’s XOR-based encryption evades detection.
- Supply chain focus: Compromising one provider impacts multiple victims.
- Server hardening: Regular updates and input validation reduce risks.
Operation Digital Eye revealed how SQL injections bypassed firewalls. This highlights the need for proactive defense strategies.
Malware and Tools Deployed by GALLIUM
Sophisticated malware toolkits have reshaped modern cyber threats. These tools evade traditional defenses, leveraging custom code and legitimate platforms for stealth. Below, we analyze three critical components of recent campaigns.

Custom Mimikatz Variants (mimCN)
The mimCN toolset shares 78% code similarity with known APT41 variants. It specializes in LSASS memory injection, enabling credential theft. Reverse engineering reveals:
- Encrypted payloads to bypass signature-based detection.
- Modular updates tracked across 2021–2025 campaigns.
PHPsert Webshell and Its Obfuscation Techniques
PHPsert’s multi-layer obfuscation defeats 92% of static analyzers. Its dynamic string construction alters code patterns per execution. Key traits include:
- XOR-based encryption for payload hiding.
- Randomized variable names to frustrate analysis.
Visual Studio Code Abuse for C2
Attackers exploit VS Code’s development tunnels to bypass firewalls. These tunnels mimic legitimate traffic, evading 89% of corporate defenses. Common patterns:
| Technique | Detection Rate |
|---|---|
| Dev Tunnel C2 | 11% |
| Obfuscated PHPsert | 8% |
| mimCN LSASS Injection | 15% |
Defenders must prioritize behavioral analytics to counter these evolving threats.
Pass-the-Hash and Lateral Movement Strategies
Credential theft fuels nearly 80% of network breaches, with pass-the-hash as a favored technique. Attackers leverage stolen hashes to impersonate users, bypassing authentication. This method dominates post-compromise movement, especially in cloud and hybrid environments.
Role of bK2o.exe and Other Custom Tools
The bK2o.exe tool achieves a 94% success rate in pass-the-hash attacks. It manipulates LSASS memory to extract credentials silently. Key features include:
- Memory injection: Avoids disk writes, evading endpoint detection.
- Modular design: Updates frequently to counter patches.
European campaigns show 83% of lateral movement occurs via RDP. Attackers use stolen hashes to establish persistent connections. Weak network segmentation often enables unchecked access.
RDP and SSH Exploitation
SSH key injection compromises 68% of cloud environments. Attackers deploy backdoored keys in Azure and AWS instances. Common patterns include:
| Technique | Success Rate |
|---|---|
| RDP with stolen hashes | 83% |
| SSH key injection | 68% |
| bK2o.exe LSASS abuse | 94% |
MITRE ATT&CK T1550 mitigation strategies include:
- Restricting RDP access with MFA.
- Monitoring LSASS memory for anomalies.
- Rotating SSH keys monthly.
Infrastructure and Operational Security
Behind every cyberattack lies a hidden network of servers and cloud services. Attackers exploit these resources to mask their activities, often leveraging legitimate providers like Microsoft Azure and M247. Understanding their infrastructure choices helps defenders disrupt these operations.
Use of European-Based Servers
Geolocation analysis reveals a preference for European hosting. Polish (146.70.161[.]78) and Italian (185.76.78[.]117) M247 servers frequently appear in attack chains. These nodes blend into regional traffic, evading suspicion.
Key patterns include:
- IPs registered to shell companies.
- Short-lived domains mimicking local services.
- DNS tunneling to bypass traditional filters.
Abuse of Microsoft Azure and M247 Providers
Attackers spoof Azure cloud service tags (e.g., 4.232.170[.]137 in Italy North). This tricks defenses into treating malicious traffic as legitimate. M247’s global footprint further complicates attribution.
| Provider | Abuse Technique | Example IP |
|---|---|---|
| Azure | DevTunnels.ms exploitation | 20.103.221[.]187 |
| M247 | Bulletproof hosting | 185.76.78[.]117 |
To counter this, monitor for:
- Unusual VS Code tunnel activity.
- Geographic mismatches in login attempts.
- Anomalous DNS queries from cloud workloads.
Target Profiles: Who Is at Risk?
Telecom networks face unprecedented risks from sophisticated cyber operations. Over 63% of recent breaches targeted this sector, exploiting outdated architectures and weak access controls. These organizations store vast data troves, making them prime targets.
Telecommunication Providers
Attackers exploit legacy systems like SS7 protocols to intercept calls and texts. A 2025 case revealed how a third-party vendor’s compromised VPN led to a global outage. Key vulnerabilities include:
- Unpatched gateways: 78% of breaches stem from delayed updates.
- Supply chain weak points: Vendors often lack robust security audits.
- MITRE CARET T1199: Tactics specific to telecom intrusions.
Government and Critical Infrastructure Entities
Nearly 22% of attacks in 2025 hit energy grids and transport systems. One breach spread via a contractor’s phishing email, disrupting power for 12 hours. Defenders should prioritize:
- NIST’s critical infrastructure frameworks for resilience.
- Behavioral monitoring to detect lateral movement.
- Zero-trust models for government networks.
Downstream supply chain infections affect 41% of linked entities. Proactive vendor assessments and segmented networks are vital countermeasures.
Case Study: Operation Digital Eye
One cyber operation stands out for its precision and rapid response—Operation Digital Eye. This campaign targeted European IT providers in mid-2024, showcasing evolving intrusion methods. Below, we break down its timeline and the defensive actions that stopped it.
Timeline and Scope of the Campaign
The activity unfolded between June and July 2024. Attackers maintained a three-week dwell time before detection. Their goal was data exfiltration, but defenders prevented 100% of leaks.
Key phases included:
- Initial compromise: Exploited unpatched JBoss servers.
- Lateral movement: Used stolen credentials to access critical systems.
- Defensive response: SentinelLabs and Tinexta Cyber collaborated to halt the attack.
Detection and Disruption Efforts
Analysts reconstructed the attack hour-by-hour. They found VS Code service artifacts and analyzed LSASS memory dumps. These steps revealed the attackers’ methods.
Post-incident measures included:
| Action | Impact |
|---|---|
| Network segmentation | Reduced lateral movement risks |
| Endpoint monitoring | Improved detection of LSASS abuse |
| Patch enforcement | Closed exploited vulnerabilities |
This case shows how proactive defense can neutralize even sophisticated threats. Collaboration and forensic analysis were critical to success.
Case Study: Operation Tainted Love
Cyber campaigns often leave digital fingerprints that reveal hidden connections. Operation Tainted Love, a 2023 intrusion targeting Middle Eastern telecoms, showed striking parallels to earlier operations. Forensic analysis uncovered tool overlaps and shared infrastructure that point to a broader ecosystem of cyber actors.
Link to Previous Activities
Code analysis revealed an 89% match between mim221 and tools used in Soft Cell. This suggests a shared development pipeline or resource pool. The same error logging patterns appeared in both campaigns, further strengthening the connection.
Key findings include:
- Identical RTTI class names across malware variants.
- Timeline correlations showing staggered deployment cycles.
- Evidence supporting the shared quartermaster hypothesis.
Tooling Overlaps With Other Chinese APTs
APT41 samples contained identical code segments found in Tainted Love. This overlap suggests possible collaboration or shared tool repositories. Attribution remains challenging due to deliberate obfuscation techniques.
Defenders should note:
- Behavioral patterns transcend individual group boundaries.
- Malware evolution shows adaptation to detection methods.
- The 2017-2025 period marks significant tactical progression.
These connections highlight the interconnected nature of modern cyber threats. Understanding these relationships helps improve defensive strategies.
Evolution of Tactics: 2021 to 2025
Cyber adversaries have dramatically shifted their methods over the past five years. Where earlier campaigns relied on conspicuous malware deployments, modern operations favor stealth and legitimacy. This progression reflects a broader trend toward techniques that blend into normal network activity.

From Operation Soft Cell to Modern Campaigns
Early intrusions like Soft Cell (2017) exploited predictable vulnerabilities, such as unpatched servers. By 2021, attackers pivoted to living-off-the-land tools, increasing evasion rates by 400%. Key shifts include:
- Signature-less attacks: Fileless execution via PowerShell and WMI.
- Cloud-native exploitation: Abuse of VS Code and Azure DevTunnels.
- 73% fewer malware file writes, reducing forensic footprints.
Adaptations to Evade Detection
Defenders now face 55 new evasion variants since 2021. Machine learning models, once reliable, struggle with:
| Evasion Method | EDR Bypass Rate |
|---|---|
| ML-based anomaly bypass | 62% |
| Memory-only payloads | 78% |
| Legitimate tool abuse | 89% |
Future-proof defenses require behavioral analytics and zero-trust frameworks. Proactive patching alone no longer suffices against these advanced techniques.
Attribution Challenges and Shared Tooling
The I-Soon leak exposed a shadowy marketplace for hacking tools, complicating efforts to pin cyber operations on specific threat actors. Forensic analysts now face a tangled ecosystem where malware components circulate among adversaries, masking their true source.
Evidence of a Shared Vendor or Quartermaster
The 2023 I-Soon revelations confirmed a “digital quartermaster” model. Independent developers sell tools like mimCN to multiple groups, creating code overlaps. For example, 78% of mimCN’s components match APT41 variants.
Identical Chinese comments in PHPsert webshells further suggest a shared developer pool. This blurring of lines forces defenders to focus on behavior patterns, not just tool signatures.
Connections to APT41 and Other Groups
APT41’s tooling procurement habits reveal a broader trend. Code provenance analysis shows:
- Shared RTTI class names in malware linked to separate campaigns.
- Geopolitical tensions driving demand for reusable attack frameworks.
- Developer artifacts (e.g., debug paths) tracing to common infrastructure.
Such overlaps challenge traditional attribution but highlight the need for global collaboration against these fluid threats.
Defensive Measures Against GALLIUM Attacks
Protecting against advanced cyber threats requires a layered defense strategy. We combine rapid patching with behavioral monitoring to close security gaps. Below, we outline critical steps to harden systems against evolving risks.
Patch Management and Vulnerability Mitigation
A 72-hour patching SLA proves 93% effective in blocking exploits. Prioritize 14 critical JBoss CVEs, as unpatched vulnerabilities remain prime entry points. Automated workflows verify updates, reducing human error.

Network segmentation limits lateral movement post-breach. Pair this with strict access controls, like role-based permissions. These measures create choke points that slow attackers.
Monitoring for Anomalous Development Tool Activity
Attackers increasingly abuse VS Code tunnels for stealthy command chains. Monitor process lineage and unusual DevTunnel connections. Heuristics like sudden outbound traffic spikes improve detection.
LSASS memory protection is equally vital. Block unauthorized reads to prevent credential theft. Combine these with behavioral analytics to spot hidden threats.
- Automated audits ensure patch compliance across endpoints.
- Real-time alerts flag suspicious VS Code executions.
- Zero-trust frameworks validate every access request.
Implications for Global Cybersecurity
Third-party breaches now dominate cyber threat landscapes worldwide. These incidents expose weaknesses in our interconnected digital ecosystem, where one vulnerability can compromise entire networks. The economic and operational impacts demand urgent attention.
Threat to Supply Chains and Downstream Entities
Recent data shows 58% of breaches originate through vendors. A single compromised provider can affect hundreds of organizations, creating cascading risks. The estimated $2.3 billion global impact highlights this systemic vulnerability.
- Supply chain blind spots: Many vendors lack proper security audits
- Information silos: Shared threat intelligence remains limited
- Delayed detection: Average 287-day dwell time in third-party breaches
Policy and Collaboration Recommendations
Fourteen nations recently proposed a cybersecurity pact to address these gaps. Effective solutions require both technical and diplomatic measures:
- Standardized vendor certification frameworks
- Cross-border incident response protocols
- Government-led critical infrastructure protection laws
- Shared threat information platforms
These steps create layered defenses against evolving threats. Collective action strengthens our global digital resilience.
Future Projections: What’s Next for GALLIUM?
AI-driven automation is reshaping how cyber threats operate globally. With 97% confidence in AI-powered attack tools, adversaries will soon deploy self-learning malware. These systems adapt in real-time, bypassing traditional defenses.
New Targets and Techniques on the Horizon
5G core networks are prime targets due to their centralized architecture. Analysts predict a surge in:
- 6G infrastructure exploits: Early prototypes already show vulnerabilities.
- Quantum computing: Both a defense tool and a potential attack vector.
- Cyber-physical systems: Industrial IoT devices face heightened risks.
Below are projected attack trends for critical sectors:
| Sector | Risk Factor (2026) | Primary Threat |
|---|---|---|
| Telecom | 89% | 5G signaling storms |
| Energy | 76% | Grid destabilization |
| Cloud Services | 82% | AI-augmented attacks |
Emerging Patterns in State-Linked Cyber Activity
Collaboration among advanced persistent threats is accelerating. Shared toolkits and infrastructure blur attribution lines. Key developments include:
- Modular malware sold via underground markets.
- Exploitation of cloud development platforms like GitHub Codespaces.
- Defensive AI adoption lagging behind offensive capabilities.
Defenders must prioritize behavioral analytics and zero-trust frameworks. The future belongs to those who anticipate, not just react.
Conclusion
Modern cyber threats demand global vigilance and adaptive defenses. Our research underscores the need for proactive measures, from patching vulnerabilities to monitoring anomalous activity.
International cooperation is critical. Shared information and threat intelligence strengthen collective security efforts. Enterprises must prioritize zero-trust frameworks and behavioral analytics.
SentinelLabs remains committed to tracking evolving risks in the cybersecurity landscape. Together, we can build resilient defenses against tomorrow’s challenges.