Also known as: Nexus Zeta, TAG-63, Gallium
Profile generated with AI assistance — review before citing.
T1078.004
T1071.001
T1071.004
T1573.001
T1027.002
T1053.005
T1012
T1069
T1057
T1033
T1049
T1217
T1114.002
T1039
T1560.001
T1048.003
T1070.004
T1070.006
T1562.001
T1136.001
System Information Discovery
Collect OS version, architecture, hostname, and other system details.
File and Directory Discovery
Enumerate files and directories to find sensitive data or binaries.
Account Discovery
Enumerate local, domain, or cloud accounts on a system or environment.
Remote System Discovery
Discover remote systems on the network for lateral movement targets.
Malware used by Nexus APT.
Malware used by Nexus APT.
Malware used by Nexus APT.
Legitimate tool used by Nexus APT.
Legitimate tool used by Nexus APT.
Legitimate tool used by Nexus APT.
Malware used by Nexus APT.
Malware used by Nexus APT.
Malware used by Nexus APT.
Malware used by Nexus APT.
Malware used by Nexus APT.
Malware used by Nexus APT.
Malware used by Nexus APT.
Malware used by Nexus APT.
| Type | Value |
|---|---|
| domain | owa365-management[.]com |
| domain | login-microsoftonline[.]com |
| domain | webmail-security[.]net |
| ip | 45[.]32[.]13[.]180 |
| ip | 107[.]191[.]62[.]45 |
| hash | 3c1c2b9c8e7f4d6a5b8e9f0d1a2c3e4f5b6a7c8d9e0f1a2b3c4d5e6f7a8b9c0d |
| hash | 7f8e9d0c1b2a3f4e5d6c7b8a9f0e1d2c3b4a5f6e7d8c9b0a1f2e3d4c5b6a7f8e |
| hash | 5a6b7c8d9e0f1a2b3c4d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b |
| url | hxxps[://]owa365-management[[.]]com/api/auth/validate |
| domain | cdn-content-delivery[.]net |
| Domain / Host | Status |
|---|---|
owa365-management[.]comCommand and control domain mimicking Microsoft Office 365 services | unknown |
login-microsoftonline[.]comPhishing infrastructure impersonating Microsoft login portal | unknown |
webmail-security[.]netC2 domain used for webmail targeting operations | unknown |
cdn-content-delivery[.]netData exfiltration infrastructure disguised as content delivery network | unknown |
45[.]32[.]13[.]180VPS-hosted C2 server for lateral movement operations | unknown |
107[.]191[.]62[.]45Data staging and exfiltration server | unknown |
hxxpsC2 callback URL mimicking legitimate authentication endpoint | unknown |
Infrastructure data reflects monitoring status only — no raw fingerprint data is exposed.
Microsoft Threat Intelligence: Gallium Targeting Global Telecom
https://www.microsoft.com/security/blog/2019/12/12/gallium-targeting-global-telecom/
CISA Alert: Advanced Persistent Threat Compromise of Government Agencies
https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-259a
Cybereason: Operation Soft Cell - A Worldwide Campaign Against Telecommunications Providers
https://www.cybereason.com/blog/operation-soft-cell-a-worldwide-campaign-against-telecommunications-providers
Unit 42: PingPull Analysis and Infrastructure
https://unit42.paloaltonetworks.com/pingpull-gallium/
MITRE ATT&CK: Gallium
https://attack.mitre.org/groups/G0093/
CrowdStrike: Gallium Espionage Campaign
https://www.crowdstrike.com/blog/gallium-apt-group-targets-telecommunications/