Water Galura — Ransomware Profile

Water Galura is Trend Micro's designation for the operators of the Qilin ransomware-as-a-service scheme, which the same vendor tracks under the malware name Agenda; Secureworks tracks the same operators as GOLD FEATHER and MITRE ATT&CK catalogues them as G1050. Trend Micro describes the group as a financially motivated RaaS operation that emerged in mid-2022 and runs a double-extortion model, with the core crew handling payload generation, ransom negotiation and leak-site publication while affiliates recruited on Russian-language cybercrime forums carry out the intrusions. No vendor or government has formally attributed the operators to a country: the Russia-nexus assessment rests on Russian-language artefacts and a CIS exclusion rule enforced in the payload, so origin is recorded here as unknown. This profile covers the same activity cluster as the separate Qilin entry on this site.

Also tracked as

GOLD FEATHER

Tools & malware

Vendor research

Read the full analysis on IntelFusions