Water Galura (GOLD FEATHER) operates the Qilin Ransomware-as-a-Service and is known for double extortion.
Analyst brief
Water Galura, also known as GOLD FEATHER, are the operators behind the Qilin Ransomware-as-a-Service (RaaS) active since at least 2022. They handle payload generation, ransom negotiations, and publication of stolen data for affiliates recruited on Russian cybercrime forums. Their key TTPs include using social media accounts for resource development, data encryption for impact (T1486), and financial theft (T1657), while leveraging Tor for anonymity. Defenders should focus on detecting Qilin ransomware indicators and unusual data exfiltration activity, as the group employs a double extortion model demanding payment for both decryption keys and non-publication of stolen data.
Water Galura
GOLD FEATHER
unknown
Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the publication of stolen data for Qilin affilates recruited on Russian cybercrime forums. Water Galura have been active since at least 2022 and use a double extortion model where they demand payment for providing decryption keys and for refraining from publishing the stolen data to their leak site.
Monitor data encryption patterns and financial transactions to detect suspicious activity related to data encryption and financial theft.
FAQ2
What role does the Water Galura actor perform in the Qilin RaaS operation?+
Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS). They handle payload generation, ransom negotiations, and the publication of stolen data to the leak site for Qilin affiliates recruited on Russian cybercrime forums.
What should defenders focus on against Water Galura's double extortion model?+
Defenders should focus on detecting Qilin ransomware indicators and unusual data exfiltration activity on the network.