Water Galura

APT / EstatalG1050 ↗
Origen🇷🇺 Rússia
Técnicas (MITRE ATT&CK)3
FuenteMITRE ATT&CK
También conocido como:GOLD FEATHER

Sobre el grupo

Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the publication of stolen data for Qilin affilates recruited on Russian cybercrime forums. Water Galura have been active since at least 2022 and use a double extortion model where they demand payment for providing decryption keys and for refraining from publishing the stolen data to their leak site.

Técnicas (MITRE ATT&CK) 3

Cómo opera el grupo, mapeado por la matriz MITRE ATT&CK y organizado por las fases de un ataque.

Vulnerabilidades explotadas

Ninguna CVE atribuida a este grupo en las fuentes públicas (MITRE ATT&CK). La ausencia de atribución no significa ausencia de actividad.

Infraestructura conocida 4

Indicadores reales (C2, dominios, URLs y hashes) asociados al malware que usa este grupo. Fuente: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

md5_hashe94148c2688de4f86df961d7ee2e8b18Qilinthreatfox
md5_hash2178e0b2e5c6058b6e39486249292f5fQilinthreatfox
md5_hash4ca3438f72d0ee6fc2c0c572db9fa866Qilinthreatfox
md5_hash687483f9b58e995b87af9ab3590333edQilinthreatfox

El grupo Water Galura usa técnicas y explota fallas reales. El Pentest Autónomo con IA de TrueHacking simula esos ataques en tu infraestructura y aporta más seguridad a tu aplicación.

Conocer el Pentest Autónomo con IA →