OAK — OnChain Attack Knowledge

Threat actor · OAK-G05

OAK-G05 — LockBit Ransomware-as-a-Service operation

Aliases
LockBit (operating brand 2019–present, with version lineage LockBit 1.0 / LockBit 2.0 a.k.a. LockBit Red / LockBit 3.0 a.k.a. LockBit Black / LockBit Green / a 2024 LockBit-NG-Dev pre-release recovered during Operation Cronos), "LockBitSupp" (the principal operator persona on Russian-language criminal forums, publicly identified May 7, 2024 as Dmitry Yuryevich Khoroshev), and the affiliate cohort named in DOJ indictments (Mikhail Vasiliev, Ruslan Magomedovich Astamirov, Mikhail Pavlovich Matveev a.k.a. "Wazawaka," Artur Sungatov, Ivan Gennadievich Kondratyev a.k.a. "Bassterlord"). For OAK-G05 purposes the cluster is the LockBit RaaS operation — the core operator network around Khoroshev plus the indicted-and-named affiliate set — not any single LockBit-encryptor variant.
First observed in crypto
approximately January 2020 (LockBit 1.0 first observed; the RaaS model with cryptocurrency-denominated ransom payments has been the operational default since inception).
Attribution status
confirmed at the operator-and-named-affiliate level — coordinated U.K. National Crime Agency / U.S. FBI / Europol "Operation Cronos" disruption announced February 20, 2024 ([nca2024operationcronos]); U.S. Treasury OFAC SDN designations of Russian nationals Artur Sungatov and Ivan Kondratyev with ten cryptocurrency addresses listed as SDN identifiers, February 20, 2024 ([ofac2024lockbitaffiliates]); U.S. Department of Justice 26-count indictment unsealed May 7, 2024 against Dmitry Yuryevich Khoroshev as the LockBit developer-and-administrator, accompanied by OFAC SDN designation of Khoroshev personally and a U.S. Department of State $10M reward ([doj2024khoroshev], [ofac2024khoroshev]); coordinated U.K. FCDO and Australia DFAT designations the same day; subsequent OFAC action against the Russian web-hosting provider Aeza Group for hosting LockBit infrastructure ([ofac2025aeza]). Attribution that specific ransom-payment flows trace through specific downstream laundering infrastructure (Garantex / OAK-G03, Sinbad mixer, Bitzlato) is inferred-strong from industry forensic providers (Chainalysis, TRM Labs) and the U.K. NCA's "Behind the Screens" wallet-tracing publication.
Active
degraded but not extinct (as of v0.1) — Operation Cronos seized 34 servers, took control of the leak site, recovered approximately 7,000 decryption keys, froze approximately 200 cryptocurrency accounts, and closed 14,000 affiliate-rogue accounts on February 19–20, 2024. Per [chainalysis2025ransomware], LockBit ransom-payment volume in H2 2024 fell approximately 79% versus H1, and the brand's market share among RaaS strains collapsed through 2024–2025. Khoroshev remained at large in Russia as of v0.1 publication (the $10M reward is for information leading to apprehension); LockBit-branded extortion activity continued at a much-reduced cadence post-Cronos, and successor or splinter-affiliate activity rebranding off the LockBit codebase is ongoing.

Description

OAK-G05 is the LockBit ransomware-as-a-service operation: a Russia-resident operator network that, between January 2020 and the February 2024 Operation Cronos disruption, was the single most prolific RaaS strain on the public record, responsible for an estimated more-than-2,000 victim organisations across at least 120 countries and over $120M in attributable extortion revenue per the DOJ. The cluster is genuinely distinct from the four prior OAK Groups: from OAK-G01 (Lazarus / DPRK direct attacks) along the state-vs-commercial-criminal axis and the crypto-native-target-vs-enterprise-IT-target axis; from OAK-G02 (Drainer-as-a-Service) along the enterprise-extortion-vs-individual-wallet-phishing axis and the attribution-strength axis (G05 is confirmed-grade, G02 is inferred-strong-grade); from OAK-G03 (Russian laundering infrastructure) along the upstream-extraction-vs-downstream-laundering axis (G05 generates illicit proceeds; G03 launders them, and G05 is a documented G03 customer); and from OAK-G04 (DPRK IT-worker placement) along the cyber-extortion-vs-employment-fraud axis. LockBit's inclusion in OAK is not because it is a crypto-native operator — its targets are overwhelmingly traditional-enterprise IT estates — but because cryptocurrency is the load-bearing payment-and-laundering rail of the entire RaaS business model, and the public attribution surface produced by Operation Cronos is one of the cleanest sanctions-and-indictment records of any single criminal operator in the on-chain economy.

The operational model is a textbook ransomware-as-a-service split: Khoroshev (LockBitSupp) developed and maintained the LockBit encryptor codebase across versions 1.0 → 2.0 → 3.0 → Green → 4.0/NG-Dev, ran the affiliate-management infrastructure (the leak-site portal, the affiliate panel, the crypto-payment routing, the negotiation chat infrastructure), and took an approximately 20% cut of ransom payments. Affiliates — independent operators who in many cases operated against multiple RaaS strains — executed the per-victim intrusions, deployed the encryptor, ran negotiation, and received ransom payments to addresses controlled by them under the service operator's supervision. Per the DOJ Khoroshev indictment, Khoroshev received approximately $100M in personal Bitcoin disbursements over the operation's lifetime. Per the U.K. NCA's post-Cronos publication, more than 2,000 Bitcoin (worth approximately $110M at the time of analysis) were identified in LockBit ransomware proceeds that had not yet been spent or laundered, and were frozen or earmarked across the affiliate-controlled wallet set. Per [chainalysis2024khoroshev], Khoroshev's personal wallet activity included transfers to Garantex (OAK-G03), the Sinbad mixer, Bitzlato, bulletproof-hosting providers, malware shops, and non-KYC underground exchanges — a textbook commercial-criminal off-ramp profile that itself shows the upstream-G05 / downstream-G03 chain at the operator-personal level.

The cluster's defender-relevant signature is upstream-extraction-cluster with confirmed-grade public attribution and a continuous downstream laundering-infrastructure dependency. Unlike OAK-G01 (which builds bespoke laundering chains using mixers, bridges, and operator-controlled cluster wallets), LockBit affiliates and the LockBit operator persona depended on third-party laundering venues that are themselves OFAC-designated (Garantex, Sinbad, Bitzlato). This makes G05 the canonical worked example of the upstream-extortion / downstream-G03-laundering chain on the commercial-criminal side of the ecosystem, structurally parallel to the upstream-G01 / downstream-G03 chain documented in the Atomic Wallet case for the state-aligned side. Defenders running Garantex and Sinbad counterparty screens against LockBit-attributed proceeds are operating at the intersection of two confirmed-grade Group attributions; the resulting watchlist surface is one of the highest-confidence cross-Group joint signals in OAK v0.1.

Targeting profile

OAK-G05's victim profile is enterprise-IT rather than crypto-native, but the value-extraction layer runs entirely through cryptocurrency:

  • Enterprise corporates across all sectors — Boeing, the Industrial and Commercial Bank of China (ICBC) U.S. broker-dealer (the November 9, 2023 attack disrupted settlement of more than $9B in U.S. Treasury-backed assets, and was specifically cited in the OFAC press release as the basis for the February 2024 designation), Royal Mail, Allen & Overy, the U.K. Ministry of Defence supplier Zaun, and approximately 2,000 other named victims.
  • Critical-infrastructure operators — hospitals, municipal governments, water utilities, schools; the U.S. CISA / FBI / ACSC / NCSC joint advisory of June 2023 documents the cross-sector targeting profile.
  • Financial-sector firms — both directly and via ICBC-class U.S.-Treasury-market-impact attacks; the financial-sector targeting was a stated escalation factor in the OFAC designation rationale.
  • Cryptocurrency-industry firms as occasional targets — present but not the dominant target class; G05 is enterprise-extortion-led, not crypto-native-extraction-led.
  • Downstream cryptocurrency users — only as secondary victims of the laundering rails the operation depends on (the load on Garantex and Sinbad from G05 flows is part of the volume that produced the OAK-G03 sanctions cycle).

Observed Techniques

OAK v0.1's Tactic catalog is on-chain-extraction-focused; LockBit's intrusion surface (off-chain enterprise IT compromise) sits outside that scope and is documented via external IDs G0237 / S1180 in the conventional cyber-threat-intel taxonomy. The on-chain Techniques observed in OAK-G05-attributable activity are concentrated on the payment-and-laundering side:

  • OAK-T7.001 (Mixer-Routed Hop) — pre-2023 default for LockBit affiliates routing ransom proceeds; usage declined sharply after the OFAC Tornado Cash designation ([ofac2022tornado]), the Sinbad takedown, and the Chipmixer takedown. Per [chainalysis2025ransomware], mixer-share of ransomware-laundering volume fell substantially across 2023–2024 as a sector-wide effect and LockBit followed the trend.
  • OAK-T7.002 (CEX Deposit-Address Layering) — the canonical post-2023 LockBit affiliate off-ramp, with Garantex deposit-address activity the named industry-forensic signature; the ten OFAC-listed addresses associated with the February 2024 LockBit-affiliate designation include deposit addresses at KuCoin, CoinsPaid, and Binance per Arkham Intelligence reporting cited in [chainalysis2024lockbit].
  • OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by NCA, Chainalysis, and TRM Labs to maintain affiliate-cluster identification across encryptor-version rotations and across the post-Cronos brand-degradation period. The persistence of affiliate-wallet-cluster identity across LockBit version rotations and across affiliate-side rebrands is the single highest-signal indicator of operator continuity in the ransomware sector and is what made the Khoroshev attribution operationally tractable.
  • Adjacent / pre-incident vectors not in OAK v0.1 scope: off-chain initial access via phishing, exposed-RDP exploitation, and exploitation of public-facing vulnerabilities (Citrix Bleed, Fortinet, Microsoft Exchange ProxyShell-class), which are the canonical LockBit-affiliate intrusion vectors. These are off-chain-IT-security-taxonomy behaviours that shape G05's operational profile but sit outside the on-chain-Tactic taxonomy at v0.1.

Observed Examples

  • Operation Cronos disruption (February 19–20, 2024). NCA-led, 11-jurisdiction action; seized 34 servers, took control of the LockBit leak-site domain (substituting NCA-branded "this site is now under the control of law enforcement" content), recovered approximately 7,000 decryption keys ([nca2024operationcronos]). OFAC same-day SDN designation of two named affiliates (Sungatov, Kondratyev) with ten crypto addresses on the SDN List as identifiers ([ofac2024lockbitaffiliates]). Attribution at confirmed.
  • Khoroshev identification and indictment (May 7, 2024). DOJ 26-count indictment unsealed against Dmitry Yuryevich Khoroshev as the LockBit developer-administrator ([doj2024khoroshev]); same-day OFAC designation ([ofac2024khoroshev]); same-day coordinated U.K. FCDO and Australia DFAT designations; U.S. State Department $10M reward. Per the indictment and [chainalysis2024khoroshev], Khoroshev received approximately $100M in personal Bitcoin disbursements over the operation's lifetime, with documented transfers to OAK-G03-cluster venues (Garantex), to mixer infrastructure (Sinbad), and to Bitzlato. Attribution at confirmed.
  • ICBC U.S. broker-dealer attack (November 9, 2023) — ~$9B in disrupted Treasury-securities settlement. Specifically cited in the February 2024 OFAC designation press release as a financial-sector escalation factor. The clearest case in the public record of a LockBit attack producing systemic-risk-class market impact rather than only victim-firm impact. Attribution at confirmed.
  • Aeza Group OFAC designation (2025). OFAC SDN designation of the Russian bulletproof-hosting provider Aeza Group for hosting LockBit (and other criminal-cohort) infrastructure ([ofac2025aeza]). Sustains the post-Cronos enforcement tempo against G05's enabling infrastructure layer. Attribution at confirmed.
  • Aggregate LockBit metrics from [doj2024khoroshev] (>2,000 victims, >$120M extortion revenue, >120 countries) and from [chainalysis2024khoroshev] (>2,000 BTC / ~$110M unspent-or-unlaundered proceeds identified by NCA blockchain analysis at the time of the May 2024 designation; H2 2024 LockBit-attributable ransom-payment volume down ~79% versus H1 per [chainalysis2025ransomware]).
  • examples/2023-11-icbc-financial-services.md — ICBC Financial Services LockBit intrusion (November 9, 2023; ~$9B Treasury-securities settlement disruption); cited in the February 2024 OFAC designation press release as a financial-sector escalation factor.
  • examples/2024-02-lockbit-operation-cronos.md — Operation Cronos international disruption action; canonical OAK-G05 attribution-and-enforcement worked example.
  • Additional G05-mediated ransom-payment laundering flow examples are pending v0.x.

Citations

  • [nca2024operationcronos] — U.K. National Crime Agency announcement of Operation Cronos and the LockBit infrastructure seizure, February 20, 2024.
  • [ofac2024lockbitaffiliates] — Treasury press release JY2114, February 20, 2024, designating Sungatov and Kondratyev with ten cryptocurrency-address SDN identifiers.
  • [doj2024khoroshev] — DOJ unsealed 26-count indictment against Dmitry Yuryevich Khoroshev, May 7, 2024.
  • [ofac2024khoroshev] — Treasury press release JY2326, May 7, 2024, designating Khoroshev as the LockBit senior leader.
  • [chainalysis2024lockbit] — Chainalysis forensic write-up of the February 2024 LockBit takedown, affiliate-wallet attribution, and SDN address analysis.
  • [chainalysis2024khoroshev] — Chainalysis forensic write-up of the Khoroshev designation, Garantex / Sinbad / Bitzlato downstream flows, and aggregate LockBit-proceeds tracing.
  • [chainalysis2025ransomware] — Chainalysis 2024-recap ransomware report documenting the post-Cronos LockBit volume collapse (H2 2024 down ~79%) and the sector-wide mixer-share decline.
  • [ofac2025aeza] — Treasury OFAC designation of the Aeza Group bulletproof-hosting provider, 2025.
  • [chainalysis2024laundering] — broader laundering-route context (companion citation; cited from G01 and G03 as well).
  • [ofac2022tornado] — sector-wide mixer-laundering enforcement context (referenced for the post-2022 ransomware-mixer-share decline, not for shared cluster identity).

Discussion

On the attribution-strength split. The LockBit operator-and-named-affiliate cluster is confirmed — coordinated NCA / FBI / OFAC / DOJ / U.K. FCDO / Australia DFAT public actions, named-defendant indictments (Vasiliev, Astamirov, Matveev, Sungatov, Kondratyev, Khoroshev), explicit cryptocurrency-address SDN listings, and a coordinated multi-jurisdiction sanctions architecture. By contrast, claims of the form "specific ransom payment X traces to specific affiliate Y within the LockBit cluster" are inferred-strong unless the specific affiliate appears in a court filing or OFAC designation; many tail-affiliate claims from industry forensics alone are inferred-strong only. OAK contributors writing G05-attributed examples should preserve this split per-incident, as with G03 and G04.

On why OAK-G05 is RaaS-operation rather than individual-affiliate and not encryptor-strain. Naming this Group entry "LockBit encryptor" would have been the conventional external-framework framing but would mis-frame the operational continuity model. The encryptor codebase has rotated across versions (1.0 → 2.0 → 3.0 → Green → 4.0/NG-Dev), partial source code has leaked publicly, and post-leak forks have produced affiliate-side rebrands; the operator-and-affiliate-cluster is a cleaner persistent identity than the strain. By the same logic, naming the Group at the individual-affiliate level (Khoroshev, Wazawaka, Bassterlord) would mis-frame the service-layer-persistence pattern that defines RaaS operationally. OAK-G05 sits at the same level of abstraction as OAK-G02 (Drainer-as-a-Service), with the difference that G05's per-named-operator attribution is confirmed-grade and G02's is inferred-strong-grade.

On the relationship to OAK-G02. G02 (Drainer-as-a-Service) and G05 (LockBit RaaS) share the commercial-service-with-affiliate-network operational model but differ along the target-class, attribution-grade, and value-per-incident axes. G02 affiliates execute many small-value individual-wallet phishing extractions; G05 affiliates execute few large-value enterprise-extortion intrusions. G02 attribution is wallet-cluster-and-industry-forensic-led and operates at inferred-strong; G05 attribution is sanctions-and-indictment-led and operates at confirmed. The two should not be conflated: a defender's anti-G02 controls (Permit2-signature warning lists, browser-extension-side phishing detection) are orthogonal to anti-G05 controls (enterprise-IT intrusion defense, ransom-payment counterparty screening).

On the relationship to OAK-G03. G03 (Russian laundering infrastructure, Garantex / Grinex / A7A5 lineage) is one of LockBit's documented downstream laundering venues, both at the affiliate-wallet level (per the SDN-listed addresses analysed in [chainalysis2024lockbit]) and at the operator-personal level (Khoroshev's documented Garantex transfers per [chainalysis2024khoroshev]). The G05 × G03 chain is the commercial-criminal-side analogue to the G01 × G03 chain documented in OAK-G03 via the Atomic Wallet example. Defenders running OAK-G03 watchlists should expect substantial overlap with G05-attributed inflows; defenders running G05 affiliate-cluster watchlists should expect substantial routing through G03-cluster venues. The two Groups are not the same threat actor but participate in a shared kill chain at high frequency.

On the relationship to OAK-G01. G01 and G05 are both upstream-extraction clusters with state-resident operating substrate (DPRK for G01, Russia for G05), but the operational model is fundamentally different: G01 is state-directed with bespoke wallet-and-laundering infrastructure under operator control; G05 is commercial-criminal with dependence on third-party laundering venues. The two clusters do not share infrastructure, do not collaborate operationally on the public record, and should not be co-clustered in defender models — they are listed in OAK as separate Groups precisely to keep this distinction explicit.

On v0.x evolution. G05's 2026+ trajectory will depend on (a) whether LockBit-branded extortion activity recovers from the post-Cronos volume collapse or whether the brand follows the Conti-2022 pattern of dispersal-into-successor-strains (Black Basta, Royal, Akira, and other Conti-successor brands); (b) whether Khoroshev or other named operators are apprehended and extradited (the $10M reward was active as of v0.1; Khoroshev remained at large in Russia); (c) whether further OFAC actions against G05's enabling infrastructure layer (Aeza-class hosting designations, additional affiliate designations) sustain the post-Cronos enforcement tempo; and (d) whether the post-Cronos collapse in LockBit market share is structural (the cluster is ending) or cyclical (the cluster is rebranding). OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates. Future OAK Group additions in the ransomware sector — Conti-successor brands, BlackCat / ALPHV (defunct after the March 2024 self-exit-scam), Cl0p, RansomHub — would each warrant their own OAK-Gnn entry rather than extension of G05, on the same per-cluster identity principle.

Software used