Water Galura
MITRE ATT&CK: G1050 View on attack.mitre.org
Aliases: GOLD FEATHER, Water Galura
- First seen
- 2022-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:30:15
Targeted industries: financial-services healthcare-and-pharmaceutical manufacturing technology-and-telecommunications transportation-and-logistics
Context
Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the publication of stolen data for Qilin affilates recruited on Russian cybercrime forums. Water Galura have been active since at least 2022 and use a double extortion model where they demand payment for providing decryption keys and for refraining from publishing the stolen data to their leak site.
Detection coverage
- 1 YARA rules
- 10 Sigma rules
Malware & tools used
Reports & references
- MITRE ATT&CK — G1050 (report)
- blog.bushidotoken.net — Tracking Adversaries Qilin Raas (report)
- news.sophos.com — Sophos Mdr Tracks Ongoing Campaign By Qilin Affiliates Targeting Screenconnect (report)