Inside GALLIUM: China’s Expanding Telecom Espionage Apparatus

GALLIUM is a China state-sponsored advanced persistent threat group active since at least 2012, specializing in cyber espionage against telecommunications, government, and critical infrastructure. Recent campaigns across Africa, Southeast Asia, and Europe highlight its use of legitimate tools like SoftEther VPN and modular malware such as ShadowPad and PlugX.

TraderTraitor: North Korea’s Crypto Heist Machine

TraderTraitor—also known as Jade Sleet and UNC4899—is one of North Korea’s most aggressive financial APT groups. Responsible for major crypto thefts, including the $1.5B ByBit hack, it targets blockchain developers, exchanges, and fintech firms worldwide.

Moonlight Tiger (APT-C-09, Patchwork, Dropping Elephant): India’s Silent Espionage Arm in the Digital Battlefield

Moonlight Tiger (APT-C-09) is a long-running India-linked cyber-espionage group conducting spearphishing, modular malware campaigns, and intelligence-gathering operations across South and East Asia. Targeting government, defense, academic, and foreign policy institutions, the group continues to evolve through living-off-the-land techniques, custom backdoors, and cloud-enabled C2 infrastructure.

APT37: North Korea’s Active Cyberespionage Group in 2025

APT37 (Famous Chollima) remains one of North Korea’s most active and adaptive cyberespionage groups. This analysis highlights their 2025 evolution—cloud persistence, AI-driven social engineering, new RAT variants, and global targeting across governments, defense, research, and policy organizations.