Google announced that it has dismantled a China-linked hacking group that had breached at least 53 organizations in 42 countries . The group, tracked by the names UNC2814 and “ Gallium ,” has been active for nearly a decade, primarily targeting government agencies and telecommunications companies .

The findings of the investigation were shared exclusively with Reuters, revealing the scope of a campaign that, according to Google, operated as a global cyberespionage.
A "massive surveillance operation" with global reach
John Hultquist, lead analyst at Google's Threat Intelligence Group, described the activity as "a massive surveillance operation" that was used to spy on organizations and individuals internationally. The group allegedly exploited cloud infrastructure and legitimate digital services to blend into regular network traffic and evade detection.
See also: SURXRAT: The expansion of an LLM-based Trojan into Android Malware
As part of the operation, Google, in collaboration with partners, terminated Google Cloud projects controlled by the perpetrators, disabled related online infrastructure , and blocked accounts used to access Google Sheets. Through these accounts, the group allegedly organized targeting and data theft operations, exploiting the platform’s credibility to “camouflage” its activity.
The company clarified that there was no violation of its products, as the abuse involved legitimate functions that were used maliciously.
Google: Confirmed violations in dozens of countries
Charlie Snyder, senior director of the same threat intelligence group, said that access to 53 entities in 42 countries has been confirmed, while there is evidence of possible activity in at least 22 more countries (before the operation was shut down).

While Google did not disclose the names of the organizations affected, it said that in one case was installed a backdoor called “GRIDTIDE. The malicious tool was deployed on a system that contained highly sensitive personal data, such as full names, phone numbers, dates and places of birth, voter ID information, and national identification numbers.
The nature of this data suggests targeted information collection with possible geopolitical implications.
See also: Microsoft: Hackers target developers with malicious Next.js repositories
Telecommunications at the center of espionage
According to Google, the targeting aligns with practices of monitoring selected targets through telecommunications infrastructure. Similar campaigns in the past have been used to steal call data records, monitor SMS messages, and even capabilities intercept to track specific individuals.
Telecommunications organizations have always been attractive targets, as they act as “hubs” for sensitive metadata and communications. Access to such systems offers a significant advantage to government or industrial espionage operations.
China's response and differentiation from "Salt Typhoon"
A Chinese embassy spokesman said cybersecurity is a common challenge for all countries and should be addressed through dialogue and cooperation. He also stressed that China opposes cyberattacks and rejects accusations that, he said, are used to defame the country.
Google clarified that this activity is different from a separate, high-profile campaign known as Salt Typhoon, which has been linked to Chinese actors and is said to have targeted hundreds of American organizations and politicians.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The growing importance of the APT threat
The UNC2814/Gallium case highlights the ongoing challenge posed by Advanced Persistent Threat (APT) groups. Through a combination of technical training, patience, and exploitation of legitimate cloud services, such groups achieve long-term persistence in networks without being detected.
See also: Russian UAC-0050 targets European financial institution
For businesses and governments, the case is a reminder that defense is not limited to installing patches, but requires continuous monitoring, access control, and analysis of anomalies in user and system behavior. In an environment where geopolitical tensions are increasingly transferred to cyberspace, the resilience of digital infrastructure is becoming a strategic priority.
Source: www.reuters.com
