Ransomware
QilinAgendaWater Galura (assessed)
Attribution
RaaS (Russian-speaking, unattributed to a state)
Origin
Unknown (Russian-speaking operators assessed)
Motivation
Financially motivated (ransomware)
Attribution confidence
medium
MENA targeting
UAE, Egypt, Saudi Arabia
Sectors
Logistics, energy, IT services, healthcare
Corpus activity · 6mo2 mentions
AMJJAS
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting UAE, Egypt, Saudi Arabia (Logistics, energy, IT services sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.