Threat Actors
20 threat actor entries, each with an explicit attribution-strength label.
Threat actors (20)
- OAK-G01 Lazarus Group / DPRK-attributed crypto theft — confirmed by FBI public statements, U.S. Treasury OFAC designations, U.S. Department of…
- OAK-G02 Drainer-as-a-Service operators — inferred-strong at the service-family level (industry forensic providers with consistent…
- OAK-G03 Russian-attributed crypto-laundering infrastructure cluster (Garantex / Grinex / A7A5 lineage) — confirmed at the infrastructure-and-named-operator level for the Garantex sub-cluster —…
- OAK-G04 DPRK IT-Worker Placement Scheme — confirmed at the scheme-and-named-facilitator level — joint U.S. State / Treasury / FBI…
- OAK-G05 LockBit Ransomware-as-a-Service operation — confirmed at the operator-and-named-affiliate level — coordinated U.K. National Crime…
- OAK-G06 Evil Corp — confirmed at the operator-and-named-defendant level — U.S. Treasury OFAC SDN designation…
- OAK-G07 APT43 / Kimsuky (DPRK espionage-and-self-funding cluster) — confirmed at the cluster-and-state-attribution level — U.S. Department of the Treasury…
- OAK-G08 BlueNoroff (DPRK financial-institution and crypto-firm intrusion sub-cluster) — confirmed at the cluster-and-state-attribution level — U.S. Department of the Treasury…
- OAK-G09 Andariel (DPRK ransomware-and-ICS sub-cluster within the Lazarus / RGB ecosystem) — confirmed at the cluster-and-state-attribution level — U.S. Department of the Treasury…
- OAK-G10 ALPHV / BlackCat Ransomware-as-a-Service operation — confirmed at the operator-cluster-and-named-affiliate level — U.S. Federal Bureau of…
- OAK-G11 Black Basta Ransomware-as-a-Service operation — confirmed at the cluster-and-tooling level — joint CISA / FBI / HHS / MS-ISAC…
- OAK-G12 Scattered Spider / UNC3944 (English-speaking financially-motivated affiliate cluster) — confirmed at the cluster-and-named-affiliate level — U.S. Department of Justice…
- OAK-G13 Iranian financially-motivated cyber operators (MuddyWater + Charming Kitten + Pioneer Kitten cluster set) — confirmed at the cluster-set-and-state-attribution level — multiple OFAC SDN…
- OAK-G14 Cl0p / Clop Ransomware-and-Data-Extortion operation — confirmed at the cluster-and-named-affiliate level — U.S. Department of the Treasury…
- OAK-G15 RansomHub Ransomware-as-a-Service operation — confirmed at the cluster-and-tooling level — joint CISA / FBI / HHS / MS-ISAC…
- OAK-G16 Akira Ransomware-as-a-Service operation — confirmed at the cluster-and-tooling level — joint CISA / FBI / Europol EC3 /…
- OAK-G17 BlackByte Ransomware-as-a-Service operation — confirmed at the cluster-and-tooling level — joint FBI / U.S. Secret Service…
- OAK-G18 Karakurt extortion-only data-theft operation — confirmed at the cluster-and-CISA-advisory level — CISA / FBI / U.S. Department of the…
- OAK-G19 DarkSide Ransomware-as-a-Service operation — confirmed — FBI attributed the Colonial Pipeline attack to DarkSide (May 2021); DOJ…
- OAK-G20 TeamPCP (cross-ecosystem supply-chain worm operator) — inferred-strong at the cluster level, self-claimed per campaign. No individual has been…