Threat actor · OAK-G03
OAK-G03 — Russian-attributed crypto-laundering infrastructure cluster (Garantex / Grinex / A7A5 lineage)
Description
OAK-G03 is the Russian-attributed crypto-laundering-infrastructure cluster: operators of services whose primary product is the off-ramping, fungibility-restoration, and sanctions-evasion layer that downstream criminal cohorts (ransomware affiliates, darknet markets, sanctions-evasion brokers, and adjacent OFAC-designated counterparties) depend on. The cluster is genuinely distinct from OAK-G01 (Lazarus / DPRK) and OAK-G02 (Drainer-as-a-Service) along three axes: (1) role in the kill chain: G03 is downstream-of-extraction infrastructure, not an extraction operator; (2) attribution surface: G03 attribution is sanctions-and-indictment-led rather than wallet-cluster-forensic-led; and (3) geographic / operational substrate: G03 entities are Russia-resident or Russia-aligned, and the cluster's resilience pattern is brand-and-domain rotation under continuous-operator control rather than wallet-infrastructure rotation under continuous-affiliate control.
The Garantex-Grinex-A7A5 lineage is the canonical worked example. Garantex Europe OÜ was incorporated under Estonian licensing in 2019 and operated as a high-throughput crypto-fiat exchange. Estonia's Financial Intelligence Unit revoked the license in February 2022 after AML/CFT deficiencies and confirmed wallet-overlap with criminal-use addresses. Treasury's April 5 2022 OFAC designation ([ofac2022garantex]), issued the same day as the Hydra Market designation, cited Garantex transactions linked to Conti ransomware ($6M direct), Hydra ($2.6M), and a broader $100M+ illicit-flow surface. Garantex continued operating from Russia post-designation. Per [treasury2025garantexnetwork], between April 2019 and March 2025 the exchange processed at least $96B in total cryptocurrency volume, and post-2022 it built infrastructure intended to prevent downstream financial institutions from attributing wallet addresses back to Garantex — an explicit anti-attribution operational posture. The DOJ indictment unsealed February 27 2025 ([doj2025garantex]) named two administrators (Besciokov, Lithuanian national, primary technical administrator; Mira Serda, Russian national, co-founder and CCO). On March 6 2025 a coordinated U.S. Secret Service / German BKA / Finnish NBI action seized three Garantex domains and servers and froze ~$26M in cryptocurrency. Besciokov was arrested in Kerala, India on March 12 2025 at U.S. request. Garantex officers created Grinex as a successor exchange immediately after the March 6 action; Treasury's August 14 2025 round designated Grinex and the A7A5 ruble-backed stablecoin network, characterising A7A5 as a sanctions-evasion vehicle processing ~$1B daily.
The cluster's defender-relevant signature is brand discontinuity under operator continuity: Garantex → Grinex is not a hostile takeover or independent successor, it is the same operator network rotating brand, domain, and stablecoin-rail to preserve service continuity in the face of enforcement. Watchlist surfaces that key off brand-name or specific OFAC-listed addresses degrade rapidly under this pattern; surfaces that key off operator-cluster wallet linkages (OAK-T8.001) or off the persistent counterparty pattern (downstream beneficiaries who continue receiving from the post-takedown successor at the same volumes they received from the pre-takedown predecessor) survive the rotation.
Targeting profile
OAK-G03 does not "target" victims in the upstream-extraction sense; the cluster's operational counterparties are:
- Ransomware operators and affiliates — Conti is the named example in the April 2022 OFAC designation; LockBit, BlackCat/ALPHV, and successor ransomware brands are documented in industry-forensic reporting as having used Garantex / successor venues for cash-out.
- Darknet markets — Hydra Market (sanctioned the same day) is the canonical example; the lineage extends through Russian-language darknet ecosystems more broadly.
- Sanctions-evasion brokers and Russia-state-adjacent off-ramp users — explicitly named in the August 2025 designation as the strategic rationale for the A7A5 network.
- Sanctions-evading high-net-worth individuals (Russian elites) — explicit framing in the Treasury press release titles for the OFAC designations.
- Downstream OFAC-designated counterparties more broadly — the cluster functions as an off-ramp-of-last-resort for entities cut off from compliant venues.
Observed Techniques
- OAK-T7.002 (CEX Deposit-Address Layering) — the canonical Technique for OAK-G03 in the sense that the cluster is the centralised-exchange-deposit-address layer for upstream criminal cohorts.
[chainalysis2024laundering]documents the broader pattern at scale; the Garantex case is the named-operator exemplar within it. - OAK-T7.003 (Cross-Chain Bridge Laundering) — secondary Technique; bridge-mediated layering routes deposits through chain-of-control transitions before reaching the G03 deposit-address surface.
- OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique that Chainalysis, Elliptic, and TRM Labs use to maintain operator-cluster identification across the Garantex → Grinex brand rotation. The persistence-of-counterparty pattern post-rotation is the single highest-signal indicator of cluster continuity.
- Adjacent / pre-incident vectors not in OAK v0.1 scope: sanctions-evasion infrastructure operation as a service (jurisdictional arbitrage, anti-attribution wallet-mapping countermeasures, ruble-backed-stablecoin-as-evasion-rail). These are governance-and-policy-layer behaviours that shape G03's operational profile but sit outside the on-chain-Tactic taxonomy at v0.1.
Observed Examples
examples/2023-06-atomic-wallet.md— Lazarus Group (OAK-G01) operation whose downstream laundering used multiple rails, of which Garantex (OAK-G03) was one. Per[ellipticatomic2023], post-extraction proceeds from the ~$100M+ Atomic Wallet incident were laundered through Garantex among several routes — Elliptic's analysis also documents flows through mixers (Sinbad / Tornado-Cash-class services) and chain-hopping rails. Atomic Wallet → Garantex is therefore one of several documented laundering rails for this incident, not the cleanest single worked example of a G01 × G03 chain. Defenders building cross-cluster watchlists should treat the Atomic Wallet case as a multi-rail G01-laundering example with G03 as one observable downstream surface, not as evidence that G03 was the dominant rail for this specific incident.- Aggregate Garantex flow metrics from
[ofac2022garantex](>$100M illicit-linked, ~$6M Conti, ~$2.6M Hydra) and from[treasury2025garantexnetwork]($96B total volume April 2019 – March 2025; ~$1B daily A7A5 processing as of designation). examples/2019-06-plus-token.md— PlusToken Ponzi cash-out flows; Chinese-cluster Ponzi but downstream BTC laundering surface intersected G03-predecessor venues (BTC-e successor infrastructure).- Worked examples for specific G03-mediated ransomware cash-out flows (Conti, LockBit cohorts) are pending v0.x and will live under
examples/once the per-incident attribution surface stabilises sufficiently for the OAK confirmed / inferred-strong distinction.
Citations
[ofac2022garantex]— original OFAC SDN designation, April 5 2022 (Treasury press release JY0701-era; same-day Hydra designation).[doj2025garantex]— DOJ Eastern District of Virginia indictment unsealed February 27, 2025 against Besciokov and Mira Serda.[treasury2025garantexnetwork]— second OFAC designation round, August 14 2025, against Grinex and the A7A5 token network.[chainalysis2025garantex]— Chainalysis forensic write-up of the international takedown action (industry-side companion to the DOJ / Treasury record).[trmlabs2025grinex]— TRM Labs forensic analysis of the Garantex → Grinex brand rotation and the A7A5 token network as sanctions-evasion infrastructure.[chainalysis2024laundering]— broader laundering-route context (companion citation; cited from G01 as well).[ellipticatomic2023]— example of upstream-G01 × downstream-G03 chain.[ofac2022tornado]— sanctions-as-attribution-source structural pattern (referenced for methodology, not for shared cluster identity).
Discussion
On the attribution-strength split. Garantex itself is confirmed — the U.S. government has issued OFAC SDN designations (twice), unsealed a federal indictment with named defendants, executed a multinational takedown, and arrested an administrator. By contrast, claims of the form "specific transaction X passed through Garantex on behalf of upstream operator Y" are inferred-strong unless they appear in a court filing or a Treasury press release naming the upstream operator (the Conti, Hydra, and Lazarus / Atomic-Wallet linkages do appear in such documents and are accordingly handled at confirmed-or-strong strength; many tail-cohort linkages from industry forensics alone are inferred-strong only). OAK contributors writing G03-attributed examples should preserve this split per-incident.
On why OAK-G03 is infrastructure-cluster rather than brand-cluster. Naming this Group entry "Garantex" would have been simpler but would mis-frame the persistence model. The Garantex → Grinex rotation in March 2025 is not the only such rotation in this ecosystem and not the last one this cluster will execute. The April 2022 Hydra designation, the September 2024 Cryptex / PM2BTC actions, and the August 2025 Grinex / A7A5 designation form a multi-year sequence in which the cluster of Russia-resident operators-of-laundering-infrastructure has rotated brands, domains, jurisdictions of incorporation, and stablecoin rails while preserving operator continuity. Defender controls (sanctions screening, exchange-side counterparty monitoring, watchlist propagation) should be designed against the cluster, not the brand.
On the relationship to OAK-G01. OAK-G01 (Lazarus / DPRK) and OAK-G03 (Russian laundering infrastructure) are upstream / downstream rather than competitive. The Atomic Wallet case ([ellipticatomic2023]) is one documented G01 × G03 example — Garantex appears as one of several laundering rails Elliptic identified for the incident, alongside mixer / Sinbad / chain-hopping routes. Defenders running OAK-G01 watchlists for incoming-flow detection at compliant venues should also be running OAK-G03 watchlists for outgoing-flow detection, because the cross-cluster handoff is where the laundering chain is most observable. The two Groups are not the same threat actor and should not be conflated, but they participate in a shared kill chain often enough that joint coverage is the operationally-correct stance. Contributors writing future G01 × G03 worked examples should preserve the multi-rail framing — G03 is typically one observable downstream surface among several, not the dominant or exclusive rail for any single G01 incident.
On the relationship to OAK-G02. OAK-G02 (Drainer-as-a-Service) and OAK-G03 share the service-layer-persistence-under-brand-rotation pattern, but the operator profile, geographic substrate, and attribution surface are different. Inferno → Angel (G02, October 2024) and Garantex → Grinex (G03, March 2025) are not the same handover phenomenon despite the surface-similar pattern; treating them as such would dilute Group-axis utility for defenders building per-cluster controls.
On v0.x evolution. The G03 cluster's 2026+ trajectory will depend on (a) whether the A7A5 network survives the August 2025 designation as a continuing operational rail, (b) whether further successor exchanges emerge from the same operator network, and (c) whether the legal proceedings against Besciokov (Kerala arrest, U.S. extradition pursuit as of March 2025) produce additional indicted operators. OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates.