← Back to all threat actors

Water Galura

Also known as GOLD FEATHER
Tracked as G1050

Water Galura are the operators of the Qilin Ransomware-as-a-Service (RaaS) who handle payload generation, ransom negotiations, and the publication of stolen data for Qilin affilates recruited on Russian cybercrime forums. Water Galura have been active since at least 2022 and use a double extortion model where they demand payment for providing decryption keys and for refraining from publishing the stolen data to their leak site.

How we source and review actor profiles
Motivation
ransomware
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
RelationshipOverlaps relationship with Qilin

MITRE tracks Water Galura as the operator cluster that runs the Qilin RaaS. The ransomware brand and operator identity remain separate profiles because they represent different analytic objects.

High
Cataloged
IdentityAlias: GOLD FEATHER

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G1050

Reviewed identity mapping approved on this date.

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

Water GaluraCanonical Name
GOLD FEATHERAlias
G1050Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...