Monday, July 15, 2024

GALLIUM APT Hackers Using New Hacking Tool “PingPull” To Attack on Telecom & Government Sectors

An APT group named GALLIUM has recently been using a new and hard-to-detect remote access trojan named PingPull. The trojan is being identified by the security experts at Unit 42 security firm as a part of their research.

In addition to monitoring several APT groups, unit 42 also monitors its own infrastructure as well. GALLIUM established its reputation by targeting telecommunications companies operating in the following regions:-

  • Southeast Asia
  • Europe
  • Africa

Prime Targets

While the APT group, Gallium state-sponsored hackers are primarily targeting the following sectors with the new “PingPull” RAT:-

  • Financial institutions
  • Government entities
  • Telecommunications

The following are the countries in which these entities are based:-

  • Australia
  • Russia
  • Philippines
  • Belgium
  • Vietnam
  • Malaysia
  • Cambodia
  • Afghanistan

Supposedly, Gallium is located in China, and it is considered that its target scope in espionage operations aligns with the lures of the country.


A threat actor can access a compromised host using PingPull, a Visual C++ application that runs commands and accesses a reverse shell. In PingPull, there are three versions without functional distinction, but each one uses its own set of protocols to communicate with its C2:-

  • ICMP
  • HTTP(S)
  • Raw TCP

There might be different C2 protocols, as actors may deploy the appropriate variant based on preliminary reconnaissance evading specific detection methods/tools associated with the detection of specific networks.

The following command-line options are supported by all three variants:-

  • Enumerate storage volumes (A: through Z:)
  • List folder contents
  • Read File
  • Write File
  • Delete File
  • Read file, convert to hexadecimal form
  • Write file, convert from hexadecimal form
  • Copy file sets the creation, write, and access times to match original files
  • Move file, sets the creation, write, and access times to match original files
  • Create directory
  • Timestomp file
  • Run command via cmd.exe

In order to decrypt these commands, the beacon needs a pair of hardcoded keys in order to decrypt them since they are sent from the C2 in AES-encrypted form.


Here below the cybersecurity researchers have recommended the following mitigations:-

  • PingPull malware is detected by Cortex XDR and protected against it. 
  • PingPull malware is correctly identified as malign by WildFire using its cloud-based threat analysis service. 
  • Make sure to use a robust Antivirus tool set.
  • Domains connected to this group are identified as malicious by advanced URL Filtering and DNS Security.

Moreover, at the moment, the APT group, Galium has also diversified its scope to include a number of key government companies as well as a number of major financial institutions.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.


Latest articles

Critical Cellopoint Secure Email Gateway Flaw Let Attackers Execute Arbitrary Code

A critical vulnerability has been discovered in the Cellopoint Secure Email Gateway, identified as...

Singapore Banks to Phase out OTPs for Bank Account Logins Within 3 Months

The Monetary Authority of Singapore (MAS) and The Association of Banks in Singapore (ABS)...

GuardZoo Android Malware Attacking military personnel via WhatsApp To Steal Sensitive Data

A Houthi-aligned group has been deploying Android surveillanceware called GuardZoo since October 2019 to...

ViperSoftX Weaponizing AutoIt & CLR For Stealthy PowerShell Execution

ViperSoftX is an advanced malware that has become more complicated since its recognition in...

Malicious NuGet Campaign Tricking Developers To Inject Malicious Code

Hackers often target NuGet as it's a popular package manager for .NET, which developers...

Akira Ransomware Attacking Airline Industry With Legitimate Tools

Airlines often become the target of hackers as they contain sensitive personal and financial...

DarkGate Malware Exploiting Excel Files And SMB File Shares

DarkGate, a Malware-as-a-Service (MaaS) platform, experienced a surge in activity since September 2023, employing...
Guru baran
Guru baran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Free Webinar

Low Rate DDoS Attack

9 of 10 sites on the AppTrana network have faced a DDoS attack in the last 30 days.
Some DDoS attacks could readily be blocked by rate-limiting, IP reputation checks and other basic mitigation methods.
More than 50% of the DDoS attacks are employing botnets to send slow DDoS attacks where millions of IPs are being employed to send one or two requests per minute..
Key takeaways include:

  • The mechanics of a low-DDoS attack
  • Fundamentals of behavioural AI and rate-limiting
  • Surgical mitigation actions to minimize false positives
  • Role of managed services in DDoS monitoring

Related Articles