Water Galura — Ransomware Profile
Water Galura is Trend Micro's designation for the operators of the Qilin ransomware-as-a-service scheme, which the same vendor tracks under the malware name Agenda; Secureworks tracks the same operators as GOLD FEATHER and MITRE ATT&CK catalogues them as G1050. Trend Micro describes the group as a financially motivated RaaS operation that emerged in mid-2022 and runs a double-extortion model, with the core crew handling payload generation, ransom negotiation and leak-site publication while affiliates recruited on Russian-language cybercrime forums carry out the intrusions. No vendor or government has formally attributed the operators to a country: the Russia-nexus assessment rests on Russian-language artefacts and a CIS exclusion rule enforced in the payload, so origin is recorded here as unknown. This profile covers the same activity cluster as the separate Qilin entry on this site.Also tracked as
GOLD FEATHER
Tools & malware
- Cobalt Strike tool
- MEGAsync tool
- NETXLOADER malware
- PsExec tool
- Qilin Ransomware
- SmokeLoader malware
- SystemBC malware
- Tor Anonymization Tool
- WinSCP tool