Gadolinium is not supported by the available facts as a distinct threat actor with attributable activity. The supplied intelligence discusses multiple China-nexus intrusion sets and specifically references APT40, APT15, and APT1 in connection with steganographic techniques, as well as broader Chinese state-linked cyber espionage targeting government, manufacturing, telecommunications, finance, energy, and critical infrastructure sectors. However, no high-confidence facts in the available material identify Gadolinium as an alias for any of those groups, define its organizational affiliation, or describe operations directly attributed to that name. As a result, a reliable encyclopedic attribution for Gadolinium is currently not available from the supplied evidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT40 is known for using steganography, specifically embedding stolen trade secrets in image files as part of its cyber espionage operations.
APT40 is a China-nexus cyber espionage group known for targeting government and manufacturing sectors, especially in the Asia-Pacific region, with a focus on maritime and energy interests.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.