Water Galura

APT / StateG1050
Origin🇷🇺 Rússia
Techniques (MITRE ATT&CK)3
SourceMITRE ATT&CK
Also known as:GOLD FEATHER

Vexday analysis

Water Galura (também identificado como GOLD FEATHER, código MITRE ATT&CK G1050) é um grupo de origem russa responsável pela operação do Ransomware-as-a-Service (RaaS) Qilin, gerenciando a geração de payloads, as negociações de resgate e a publicação de dados exfiltrados em nome de afiliados recrutados em fóruns de cibercrime russos. O grupo está ativo desde pelo menos 2022 e adota o modelo de dupla extorsão, exigindo pagamento tanto pela entrega de chaves de descriptografia quanto pela retenção da publicação dos dados roubados em seu site de vazamentos. Ao todo, 3 técnicas MITRE ATT&CK foram documentadas para esse grupo.

Techniques (MITRE ATT&CK) 3

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 4

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

md5_hashe94148c2688de4f86df961d7ee2e8b18Qilinthreatfox
md5_hash2178e0b2e5c6058b6e39486249292f5fQilinthreatfox
md5_hash4ca3438f72d0ee6fc2c0c572db9fa866Qilinthreatfox
md5_hash687483f9b58e995b87af9ab3590333edQilinthreatfox

Water Galura uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →