>samit_hota
Back to adversary profiles
G1050CriticalActive

Water Galura (GOLD FEATHER) Threat Actor Profile

Samit Hota·
Suspected Origin
Russian-speaking
Motivation
Financial Gain
Aliases
GOLD FEATHER
Target Sectors
Manufacturing, Professional Services, Retail and Hospitality, Technology, Construction and Engineering, Healthcare, Education, Government, Financial Services, Critical Infrastructure
Associated Malware
Qilin Ransomware, Agenda Ransomware, SmokeLoader, NETXLOADER, Cobalt Strike
#threat-actor#g1050

Overview

Water Galura (G1050), also known by the aliases GOLD FEATHER, Qilin, Agenda, and occasionally Phantom Mantis, is a highly active and financially motivated cybercrime group operating a sophisticated Ransomware-as-a-Service (RaaS) scheme. The group has been operational since at least mid-2022, with initial instances of their ransomware observed in July 2022. Water Galura employs a double extortion model, encrypting victim files to disrupt operations and exfiltrating sensitive data, which they then threaten to publish on their dedicated Tor-based leak site if ransom demands are not met.

Attribution evidence strongly points to a Russian-speaking origin for Water Galura. The group actively recruits affiliates through exclusive Russian cybercrime forums, such as RAMP (Ransom Anon Market Place), and adheres to the common practice among Russia-linked threat actors of avoiding targets within Commonwealth of Independent States (CIS) countries. Their RaaS model is highly professionalized; the core Water Galura operators are responsible for developing and maintaining the Qilin ransomware payloads, managing the supporting infrastructure, handling ransom negotiations, and publishing stolen data. Affiliates, who are external cybercriminals recruited from forums, execute the intrusions, deploying the ransomware and stealing data. They receive a substantial percentage of paid ransoms, with their cut potentially rising to 80-85% for larger payments exceeding $3 million.

Water Galura’s targeting approach is opportunistic, primarily driven by exploitable vulnerabilities and access availability rather than strict sector-specific focus. However, they consistently target high-value organizations with a low tolerance for downtime across a broad range of industries. Predominant sectors include manufacturing, professional services, retail and hospitality, technology, construction and engineering, healthcare, education, government (State, Local, Tribal, and Territorial), financial services, and critical infrastructure. Geographically, their impact is widespread, with a high concentration of victims in North America and Western Europe, specifically the United States, Canada, the United Kingdom, France, and Germany.

Tactics & Techniques

Water Galura affiliates leverage a diverse array of tactics and techniques to gain initial access, establish persistence, move laterally, and execute their ransomware. Initial access often involves exploiting publicly exposed applications and services, including known vulnerabilities in Fortinet (CVE-2024-21762, CVE-2024-55591), JetBrains TeamCity, and Veeam Backup & Replication (CVE-2023-27532). They also utilize phishing campaigns, sometimes spoofing legitimate services like ScreenConnect remote monitoring and management tools, to acquire administrative credentials. The abuse of weak or compromised remote services such as Remote Desktop Protocol (RDP) and Virtual Private Networks (VPNs) is another common entry vector, frequently facilitated by leaked administrative credentials obtained from the dark web.

Once inside a network, Water Galura affiliates employ various legitimate tools for their operations. They frequently abuse Remote Monitoring and Management (RMM) software like AnyDesk, ScreenConnect, Splashtop, Chrome Remote Desktop, Distant Desktop, GoToDesk, and QuickAssist for command execution, persistent remote access, and ultimately, ransomware deployment. For lateral movement, they rely on tools such as PsExec, NetExec, WinRM, and Server Message Block (SMB) and Windows administrative shares. They have been observed enabling SSH access on ESXi hosts and using PuTTY for connections and file transfers. The group also utilizes Cobalt Strike for post-exploitation activities and command and control.

For defense evasion, Water Galura employs sophisticated techniques including terminating security-related services and processes (antivirus, EDR), clearing Windows Event logs to hinder forensic analysis, and deleting the ransomware payload itself after execution. They have also used “Bring Your Own Vulnerable Driver” (BYOVD) methods to disable security tools and gain system access. Rebooting systems in safe mode to bypass security controls and disguising malicious executables as legitimate applications are also part of their evasion playbook. Credential access is achieved through memory dumps (e.g., LSASS, KeePass) and harvesting credentials from web browsers like Chrome, as well as specialized tools targeting backup infrastructure. Water Galura also exhibits capabilities for enumerating domain-connected hosts and VMware vCenter and ESXi environments. They have been observed modifying root passwords for ESXi hosts, effectively locking out victims even after encryption.

Notable Campaigns

Water Galura has been linked to numerous high-impact incidents, particularly gaining notoriety in 2024 and 2025. One of their most significant attacks occurred in June 2024, targeting Synnovis, a UK-based medical company providing pathology services to major National Health Service (NHS) hospitals in London. This incident, which included a $50 million ransom demand and the exfiltration of 400GB of patient data, severely disrupted healthcare services, leading to the cancellation of thousands of operations and appointments.

Other notable incidents include an attack on an Australian court system in January 2024, involving the exfiltration of court files and audio-visual archives, and a May 2025 attack on Cobb County, Georgia, where 150GB of sensitive data, including autopsy photos and personal records, were acquired. In April 2025, SK Inc., a firm with significant investments in US businesses, also fell victim, with over 1TB of files exfiltrated. More recently, in March 2026, Water Galura claimed responsibility for a cyberattack against Die Linke, a German left-wing political party, which led to parts of its IT systems being taken offline.

Beyond direct attacks, Water Galura has engaged in unconventional extortion tactics, such as launching a website, an X (formerly Twitter) account, and a Telegram channel in early 2024 that exploited the WikiLeaks brand. These platforms were used to tarnish the reputations of victims who refused to pay, aiming to pressure them into capitulating and encouraging future victims to comply with ransom demands. The group’s activity saw a significant increase in 2024 and 2025, largely benefiting from the disruption of other prominent RaaS groups like ALPHV/BlackCat, LockBit, and RansomHub, attracting displaced affiliates to its robust platform. Notably, in 2025, Microsoft reported observing Moonstone Sleet, a North Korea-linked state actor, deploying Qilin ransomware in limited, targeted operations, marking an unusual instance of a state-linked actor using a RaaS variant.

Associated Malware & Tools

The primary malware associated with Water Galura is the Qilin ransomware, also known by its precursor name, Agenda ransomware. Initially developed in Golang, the ransomware later evolved into a more sophisticated Rust-based variant, offering cross-platform capabilities to target Windows, Linux, and VMware ESXi environments. Qilin payloads are highly configurable, allowing affiliates to customize encryption modes (e.g., normal, step-skip, fast, percent), specify files/directories to exclude, define services/processes to terminate, and tailor evasion techniques for each victim. An advanced version, Qilin.B, has been identified, which provides enhanced encryption and evasion capabilities. The ransomware utilizes strong encryption algorithms such as ChaCha20, AES-256-CTR, and RSA-4096.

In addition to the core ransomware, Water Galura affiliates employ various loaders and post-exploitation tools. These include SmokeLoader and NETXLOADER, which is often packed with .NET Reactor v6 for obfuscation. For network reconnaissance and lateral movement, they commonly use legitimate system administration tools like PsExec, NetExec, and WinRM. Remote access tools such as AnyDesk, ScreenConnect, Splashtop, Chrome Remote Desktop, Distant Desktop, GoToDesk, and QuickAssist are leveraged to maintain access and facilitate operations. Command and control often involves Cobalt Strike, while PuTTY is used for establishing SSH connections, particularly in Linux and VMware environments. For credential harvesting, affiliates may deploy tools like Mimikatz and LaZagne. The group’s operational infrastructure includes a Telegram news channel for RaaS announcements and Tor-hosted data leak sites.

Current Status

Water Galura remains a highly active and formidable threat in the ransomware landscape. Throughout 2024 and 2025, the group experienced significant growth, rapidly becoming one of the most prolific RaaS operations globally, often ranking among the top ransomware groups in terms of victim count. According to some analyses, Qilin ransomware claimed approximately 1,600 victims within a single year and over 500 victims in 2026 alone.

While there was a reported slight decrease in victim postings in June 2026, causing Qilin to fall from the top spot in some rankings, it still accounted for a substantial number of attacks (80 victims) in that month, indicating sustained activity. This minor dip is not necessarily indicative of a long-term decline, as the group continues to refine its tooling, expand its affiliate program, and innovate its extortion strategies. Water Galura has recently expanded its RaaS ecosystem to offer unique features such as legal and media support for negotiations, large-scale (PB-scale) data storage, and even DDoS capabilities to increase pressure on victims. Given its robust RaaS model, adaptability, and continuous recruitment of affiliates, Water Galura is expected to remain a persistent and relevant threat in the immediate future, continuing to target high-value organizations across various critical sectors worldwide.

Worried this actor targets your sector?

Let's map your exposure before they find it themselves.

Book an advisory call