Water Galura

APT / StateG1050 ↗
Origin🇷🇺 Rússia
Techniques (MITRE ATT&CK)3
SourceMITRE ATT&CK
Also known as:GOLD FEATHER

About the group

Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the publication of stolen data for Qilin affilates recruited on Russian cybercrime forums. Water Galura have been active since at least 2022 and use a double extortion model where they demand payment for providing decryption keys and for refraining from publishing the stolen data to their leak site.

Techniques (MITRE ATT&CK) 3

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 4

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

md5_hashe94148c2688de4f86df961d7ee2e8b18Qilinthreatfox
md5_hash2178e0b2e5c6058b6e39486249292f5fQilinthreatfox
md5_hash4ca3438f72d0ee6fc2c0c572db9fa866Qilinthreatfox
md5_hash687483f9b58e995b87af9ab3590333edQilinthreatfox

Water Galura uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →