ATT&CKGroupsWater Galura

Water Galura

G1050

Threat group.View on attack.mitre.org

About this group

Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the publication of stolen data for Qilin affilates recruited on Russian cybercrime forums. Water Galura have been active since at least 2022 and use a double extortion model where they demand payment for providing decryption keys and for refraining from publishing the stolen data to their leak site.

Techniques used3

Procedure examples3

TechniqueProcedure example
T1486
Data Encrypted for Impact

Water Galura has encrypted files on victim networks through the generation of Qilin ransomware payloads.

T1585.001
Social Media Accounts

Water Galura operates a news channel on Telegram to make announcements for the Qilin RaaS.

T1657
Financial Theft

Water Galura has extorted victims for ransomware decryption keys and to prevent publication of data exfiltrated to their Tor data leak site.

Software2

Campaigns0

None recorded.

References2

  1. BushidoToken Qilin RaaS JUN 2024 Open source
    Thomas, W. (2024, June 12). Tracking Adversaries: The Qilin RaaS. Retrieved September 26, 2025.
  2. Sophos Qilin MSP APR 2025 Open source
    Bradshaw, A. et al. (2025, April 1). Qilin affiliates spear-phish MSP ScreenConnect admin, targeting customers downstream. Retrieved September 26, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.