Water Galura

MITRE ATT&CK: G1050 View on attack.mitre.org

Aliases: GOLD FEATHER, Water Galura

First seen
2022-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:30:15

Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications transportation-and-logistics

Context

Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the publication of stolen data for Qilin affilates recruited on Russian cybercrime forums. Water Galura have been active since at least 2022 and use a double extortion model where they demand payment for providing decryption keys and for refraining from publishing the stolen data to their leak site.

Detection coverage

  • 1 YARA rules
  • 10 Sigma rules

Malware & tools used

  • Social Media Accounts (attack-pattern)
  • Data Encrypted for Impact (attack-pattern)
  • Financial Theft (attack-pattern)
  • Qilin (malware)
  • Tor (malware)

Reports & references

  • MITRE ATT&CK — G1050 (report)
  • blog.bushidotoken.net — Tracking Adversaries Qilin Raas (report)
  • news.sophos.com — Sophos Mdr Tracks Ongoing Campaign By Qilin Affiliates Targeting Screenconnect (report)

External references