Security News > 2022 > June > Gallium hackers backdoor finance, govt orgs using new PingPull malware

Gallium hackers backdoor finance, govt orgs using new PingPull malware
2022-06-13 21:56

The Gallium state-sponsored hacking group has been spotted using a new 'PingPull' remote access trojan against financial institutions and government entities in Europe, Southeast Asia, and Africa.

Gallium is believed to originate from China, and its targeting scope of the telecommunications, finance, and government sectors in espionage operations aligns with the country's interests.

In recent campaigns, Gallium is employing a new RAT named PingPull, which analysts at Unit42 characterize as particularly stealthy.

The PingPull malware is designed to give threat actors a reverse shell on the compromised machine, allowing them to execute commands remotely.

This snapshot of recent Gallium campaigns revealed a new RAT, which indicates that the hacking group is still an active and evolving threat.

Based on the most recent reports, Gallium has expanded that scope to include key government entities and financial institutions in Asia, Africa, Europe, and Australia.


News URL

https://www.bleepingcomputer.com/news/security/gallium-hackers-backdoor-finance-govt-orgs-using-new-pingpull-malware/