Threat group.View on attack.mitre.org
Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the publication of stolen data for Qilin affilates recruited on Russian cybercrime forums. Water Galura have been active since at least 2022 and use a double extortion model where they demand payment for providing decryption keys and for refraining from publishing the stolen data to their leak site.
| Technique | Procedure example |
|---|---|
| T1486 Data Encrypted for Impact |
Water Galura has encrypted files on victim networks through the generation of Qilin ransomware payloads. |
| T1585.001 Social Media Accounts |
Water Galura operates a news channel on Telegram to make announcements for the Qilin RaaS. |
| T1657 Financial Theft |
Water Galura has extorted victims for ransomware decryption keys and to prevent publication of data exfiltrated to their Tor data leak site. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.