Microsoft has revealed information about a hacking group with infrastructure in China and Hong Kong. The hacking group is called Gallium and mainly targets telecommunications companies.
According to the information provided by Microsoft, the hackers of this group have been active since 2018 and use cheap tools. All they care about is compromising the systems . Once they have infiltrated the system, they are not interested in covering their tracks or their intentions.
Microsoft does not consider the Gallium group to be a serious threat or a sophisticated group, but the easy and dirty techniques it has used have proven effective.
First, attackers scan the internet to find exposed and vulnerable web servers. Then, they use common exploits to attack them.
“Compromising a web server gives Gallium an entry point into the network that does not require user interaction, like traditional methods (e.g. phishing),” Microsoft warns.
“After exploiting web servers, Gallium hackers typically install web shells and then install additional tools that allow them to explore the target network.”

Microsoft emphasizes that Galium hackers modify off-the-shelf malware tools to avoid detection by antivirus software , not to develop specific functionality.
The tools commonly used by the group (slightly modified) are: HTRAN, Mimikatz, NBTScan, Netcat, PsExec, Windows Credential Editor and WinRAR. Mimikatz is used to steal credentials after entering the network.
The hacking group also uses a modified version of the Poison Ivy RAT, a variant of the Gh0st RAT called QuarkBandit, the China Chopper web shell , and the BlackMould IIS web shell.
According to Microsoft, the Galium group has limited its attacks in recent months, but security experts should be vigilant to counter or better yet prevent a potential attack.
