UNC2814 AKA „Gallium“ attacks have been detected in Bosnia and Herzegovina
UNC2814, a sophisticated, long-standing cyber-intelligence group, also known as „Gallium“, believed to have ties to China, has found itself under the spotlight in Bosnia and Herzegovina, as a recent Google Threat Intelligence Group report about actions of this group has identified Bosnia and Herzegovina as one of the countries with suspected or confirmed UNC2814 victims.
UNC2814 has been active since 2017, recently attracting attention after using the GRIDTIDE malware to gain backdoor access into telecommunication servers, seeking to access sensitive information and disrupt telecommunication services globally.
Another point of concern is the recent GDPR-compliant Law on the Protection of Private Information in BiH, dictating penalties as high as 40 million BAM for critical personal data leaks, which could exert additional financial pressure on public and private telecommunication service providers which are already fending off a large volume of cyber attacks.
In a recent FENA (News Agency of the Federation of BiH) interview, dr. Nerma Halilović-Kibrić of the Faculty of Criminal Studies, Criminology and Security Studies has stated that Bosnia and Herzegovina being identified as one of the targeted nations has severe political and security implications. Dr. Halilović-Kibrić further stated that these attacks are not random cybercrime, but that they carry deep strategic interests for data and communications inside of our institutions.
Bosnia and Herzegovina being targeted by a PRC-proxy cyber-intelligence group should signal institutions that cyber resilience must be taken seriously and that cyber defense capacities are not desirable but necessary. This also sends a strong signal to all private enterprises that their cyber defenses need to be upgraded, improved and on high alert for stopping potential intrusions into their systems.
At a time of heightened and rapidly developing red-team capacities and operations, cyber resilience is not optional.
[ Direct Line ]
Talk to Our Security Operations Team
If this briefing is relevant to your environment, our team can assess your exposure and show you how Outis defends critical infrastructure.




