[threat-actors] Add GALLIUM aliases

This commit is contained in:
Mathieu4141 2024-02-01 11:01:57 -08:00
parent c81b10b3f5
commit 05cf259436

View file

@ -9061,15 +9061,18 @@
{
"description": "GALLIUM, is a threat actor believed to be targeting telecommunication providers over the world, mostly South-East Asia, Europe and Africa. To compromise targeted networks, GALLIUM target unpatched internet-facing services using publicly available exploits and have been known to target vulnerabilities in WildFly/JBoss.",
"meta": {
"country": "CN",
"refs": [
"https://www.microsoft.com/security/blog/2019/12/12/gallium-targeting-global-telecom/",
"https://www.youtube.com/watch?v=fBFm2fiEPTg",
"https://troopers.de/troopers22/talks/7cv8pz/",
"https://unit42.paloaltonetworks.com/atoms/alloytaurus/"
"https://unit42.paloaltonetworks.com/atoms/alloytaurus/",
"https://unit42.paloaltonetworks.com/alloy-taurus-targets-se-asian-government/"
],
"synonyms": [
"Red Dev 4",
"Alloy Taurus"
"Alloy Taurus",
"Granite Typhoon"
]
},
"related": [