Threat actor · OAK-G05
OAK-G05 — LockBit Ransomware-as-a-Service operation
Description
OAK-G05 is the LockBit ransomware-as-a-service operation: a Russia-resident operator network that, between January 2020 and the February 2024 Operation Cronos disruption, was the single most prolific RaaS strain on the public record, responsible for an estimated more-than-2,000 victim organisations across at least 120 countries and over $120M in attributable extortion revenue per the DOJ. The cluster is genuinely distinct from the four prior OAK Groups: from OAK-G01 (Lazarus / DPRK direct attacks) along the state-vs-commercial-criminal axis and the crypto-native-target-vs-enterprise-IT-target axis; from OAK-G02 (Drainer-as-a-Service) along the enterprise-extortion-vs-individual-wallet-phishing axis and the attribution-strength axis (G05 is confirmed-grade, G02 is inferred-strong-grade); from OAK-G03 (Russian laundering infrastructure) along the upstream-extraction-vs-downstream-laundering axis (G05 generates illicit proceeds; G03 launders them, and G05 is a documented G03 customer); and from OAK-G04 (DPRK IT-worker placement) along the cyber-extortion-vs-employment-fraud axis. LockBit's inclusion in OAK is not because it is a crypto-native operator — its targets are overwhelmingly traditional-enterprise IT estates — but because cryptocurrency is the load-bearing payment-and-laundering rail of the entire RaaS business model, and the public attribution surface produced by Operation Cronos is one of the cleanest sanctions-and-indictment records of any single criminal operator in the on-chain economy.
The operational model is a textbook ransomware-as-a-service split: Khoroshev (LockBitSupp) developed and maintained the LockBit encryptor codebase across versions 1.0 → 2.0 → 3.0 → Green → 4.0/NG-Dev, ran the affiliate-management infrastructure (the leak-site portal, the affiliate panel, the crypto-payment routing, the negotiation chat infrastructure), and took an approximately 20% cut of ransom payments. Affiliates — independent operators who in many cases operated against multiple RaaS strains — executed the per-victim intrusions, deployed the encryptor, ran negotiation, and received ransom payments to addresses controlled by them under the service operator's supervision. Per the DOJ Khoroshev indictment, Khoroshev received approximately $100M in personal Bitcoin disbursements over the operation's lifetime. Per the U.K. NCA's post-Cronos publication, more than 2,000 Bitcoin (worth approximately $110M at the time of analysis) were identified in LockBit ransomware proceeds that had not yet been spent or laundered, and were frozen or earmarked across the affiliate-controlled wallet set. Per [chainalysis2024khoroshev], Khoroshev's personal wallet activity included transfers to Garantex (OAK-G03), the Sinbad mixer, Bitzlato, bulletproof-hosting providers, malware shops, and non-KYC underground exchanges — a textbook commercial-criminal off-ramp profile that itself shows the upstream-G05 / downstream-G03 chain at the operator-personal level.
The cluster's defender-relevant signature is upstream-extraction-cluster with confirmed-grade public attribution and a continuous downstream laundering-infrastructure dependency. Unlike OAK-G01 (which builds bespoke laundering chains using mixers, bridges, and operator-controlled cluster wallets), LockBit affiliates and the LockBit operator persona depended on third-party laundering venues that are themselves OFAC-designated (Garantex, Sinbad, Bitzlato). This makes G05 the canonical worked example of the upstream-extortion / downstream-G03-laundering chain on the commercial-criminal side of the ecosystem, structurally parallel to the upstream-G01 / downstream-G03 chain documented in the Atomic Wallet case for the state-aligned side. Defenders running Garantex and Sinbad counterparty screens against LockBit-attributed proceeds are operating at the intersection of two confirmed-grade Group attributions; the resulting watchlist surface is one of the highest-confidence cross-Group joint signals in OAK v0.1.
Targeting profile
OAK-G05's victim profile is enterprise-IT rather than crypto-native, but the value-extraction layer runs entirely through cryptocurrency:
- Enterprise corporates across all sectors — Boeing, the Industrial and Commercial Bank of China (ICBC) U.S. broker-dealer (the November 9, 2023 attack disrupted settlement of more than $9B in U.S. Treasury-backed assets, and was specifically cited in the OFAC press release as the basis for the February 2024 designation), Royal Mail, Allen & Overy, the U.K. Ministry of Defence supplier Zaun, and approximately 2,000 other named victims.
- Critical-infrastructure operators — hospitals, municipal governments, water utilities, schools; the U.S. CISA / FBI / ACSC / NCSC joint advisory of June 2023 documents the cross-sector targeting profile.
- Financial-sector firms — both directly and via ICBC-class U.S.-Treasury-market-impact attacks; the financial-sector targeting was a stated escalation factor in the OFAC designation rationale.
- Cryptocurrency-industry firms as occasional targets — present but not the dominant target class; G05 is enterprise-extortion-led, not crypto-native-extraction-led.
- Downstream cryptocurrency users — only as secondary victims of the laundering rails the operation depends on (the load on Garantex and Sinbad from G05 flows is part of the volume that produced the OAK-G03 sanctions cycle).
Observed Techniques
OAK v0.1's Tactic catalog is on-chain-extraction-focused; LockBit's intrusion surface (off-chain enterprise IT compromise) sits outside that scope and is documented via external IDs G0237 / S1180 in the conventional cyber-threat-intel taxonomy. The on-chain Techniques observed in OAK-G05-attributable activity are concentrated on the payment-and-laundering side:
- OAK-T7.001 (Mixer-Routed Hop) — pre-2023 default for LockBit affiliates routing ransom proceeds; usage declined sharply after the OFAC Tornado Cash designation (
[ofac2022tornado]), the Sinbad takedown, and the Chipmixer takedown. Per[chainalysis2025ransomware], mixer-share of ransomware-laundering volume fell substantially across 2023–2024 as a sector-wide effect and LockBit followed the trend. - OAK-T7.002 (CEX Deposit-Address Layering) — the canonical post-2023 LockBit affiliate off-ramp, with Garantex deposit-address activity the named industry-forensic signature; the ten OFAC-listed addresses associated with the February 2024 LockBit-affiliate designation include deposit addresses at KuCoin, CoinsPaid, and Binance per Arkham Intelligence reporting cited in
[chainalysis2024lockbit]. - OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by NCA, Chainalysis, and TRM Labs to maintain affiliate-cluster identification across encryptor-version rotations and across the post-Cronos brand-degradation period. The persistence of affiliate-wallet-cluster identity across LockBit version rotations and across affiliate-side rebrands is the single highest-signal indicator of operator continuity in the ransomware sector and is what made the Khoroshev attribution operationally tractable.
- Adjacent / pre-incident vectors not in OAK v0.1 scope: off-chain initial access via phishing, exposed-RDP exploitation, and exploitation of public-facing vulnerabilities (Citrix Bleed, Fortinet, Microsoft Exchange ProxyShell-class), which are the canonical LockBit-affiliate intrusion vectors. These are off-chain-IT-security-taxonomy behaviours that shape G05's operational profile but sit outside the on-chain-Tactic taxonomy at v0.1.
Observed Examples
- Operation Cronos disruption (February 19–20, 2024). NCA-led, 11-jurisdiction action; seized 34 servers, took control of the LockBit leak-site domain (substituting NCA-branded "this site is now under the control of law enforcement" content), recovered approximately 7,000 decryption keys (
[nca2024operationcronos]). OFAC same-day SDN designation of two named affiliates (Sungatov, Kondratyev) with ten crypto addresses on the SDN List as identifiers ([ofac2024lockbitaffiliates]). Attribution at confirmed. - Khoroshev identification and indictment (May 7, 2024). DOJ 26-count indictment unsealed against Dmitry Yuryevich Khoroshev as the LockBit developer-administrator (
[doj2024khoroshev]); same-day OFAC designation ([ofac2024khoroshev]); same-day coordinated U.K. FCDO and Australia DFAT designations; U.S. State Department $10M reward. Per the indictment and[chainalysis2024khoroshev], Khoroshev received approximately $100M in personal Bitcoin disbursements over the operation's lifetime, with documented transfers to OAK-G03-cluster venues (Garantex), to mixer infrastructure (Sinbad), and to Bitzlato. Attribution at confirmed. - ICBC U.S. broker-dealer attack (November 9, 2023) — ~$9B in disrupted Treasury-securities settlement. Specifically cited in the February 2024 OFAC designation press release as a financial-sector escalation factor. The clearest case in the public record of a LockBit attack producing systemic-risk-class market impact rather than only victim-firm impact. Attribution at confirmed.
- Aeza Group OFAC designation (2025). OFAC SDN designation of the Russian bulletproof-hosting provider Aeza Group for hosting LockBit (and other criminal-cohort) infrastructure (
[ofac2025aeza]). Sustains the post-Cronos enforcement tempo against G05's enabling infrastructure layer. Attribution at confirmed. - Aggregate LockBit metrics from
[doj2024khoroshev](>2,000 victims, >$120M extortion revenue, >120 countries) and from[chainalysis2024khoroshev](>2,000 BTC / ~$110M unspent-or-unlaundered proceeds identified by NCA blockchain analysis at the time of the May 2024 designation; H2 2024 LockBit-attributable ransom-payment volume down ~79% versus H1 per[chainalysis2025ransomware]). examples/2023-11-icbc-financial-services.md— ICBC Financial Services LockBit intrusion (November 9, 2023; ~$9B Treasury-securities settlement disruption); cited in the February 2024 OFAC designation press release as a financial-sector escalation factor.examples/2024-02-lockbit-operation-cronos.md— Operation Cronos international disruption action; canonical OAK-G05 attribution-and-enforcement worked example.- Additional G05-mediated ransom-payment laundering flow examples are pending v0.x.
Citations
[nca2024operationcronos]— U.K. National Crime Agency announcement of Operation Cronos and the LockBit infrastructure seizure, February 20, 2024.[ofac2024lockbitaffiliates]— Treasury press release JY2114, February 20, 2024, designating Sungatov and Kondratyev with ten cryptocurrency-address SDN identifiers.[doj2024khoroshev]— DOJ unsealed 26-count indictment against Dmitry Yuryevich Khoroshev, May 7, 2024.[ofac2024khoroshev]— Treasury press release JY2326, May 7, 2024, designating Khoroshev as the LockBit senior leader.[chainalysis2024lockbit]— Chainalysis forensic write-up of the February 2024 LockBit takedown, affiliate-wallet attribution, and SDN address analysis.[chainalysis2024khoroshev]— Chainalysis forensic write-up of the Khoroshev designation, Garantex / Sinbad / Bitzlato downstream flows, and aggregate LockBit-proceeds tracing.[chainalysis2025ransomware]— Chainalysis 2024-recap ransomware report documenting the post-Cronos LockBit volume collapse (H2 2024 down ~79%) and the sector-wide mixer-share decline.[ofac2025aeza]— Treasury OFAC designation of the Aeza Group bulletproof-hosting provider, 2025.[chainalysis2024laundering]— broader laundering-route context (companion citation; cited from G01 and G03 as well).[ofac2022tornado]— sector-wide mixer-laundering enforcement context (referenced for the post-2022 ransomware-mixer-share decline, not for shared cluster identity).
Discussion
On the attribution-strength split. The LockBit operator-and-named-affiliate cluster is confirmed — coordinated NCA / FBI / OFAC / DOJ / U.K. FCDO / Australia DFAT public actions, named-defendant indictments (Vasiliev, Astamirov, Matveev, Sungatov, Kondratyev, Khoroshev), explicit cryptocurrency-address SDN listings, and a coordinated multi-jurisdiction sanctions architecture. By contrast, claims of the form "specific ransom payment X traces to specific affiliate Y within the LockBit cluster" are inferred-strong unless the specific affiliate appears in a court filing or OFAC designation; many tail-affiliate claims from industry forensics alone are inferred-strong only. OAK contributors writing G05-attributed examples should preserve this split per-incident, as with G03 and G04.
On why OAK-G05 is RaaS-operation rather than individual-affiliate and not encryptor-strain. Naming this Group entry "LockBit encryptor" would have been the conventional external-framework framing but would mis-frame the operational continuity model. The encryptor codebase has rotated across versions (1.0 → 2.0 → 3.0 → Green → 4.0/NG-Dev), partial source code has leaked publicly, and post-leak forks have produced affiliate-side rebrands; the operator-and-affiliate-cluster is a cleaner persistent identity than the strain. By the same logic, naming the Group at the individual-affiliate level (Khoroshev, Wazawaka, Bassterlord) would mis-frame the service-layer-persistence pattern that defines RaaS operationally. OAK-G05 sits at the same level of abstraction as OAK-G02 (Drainer-as-a-Service), with the difference that G05's per-named-operator attribution is confirmed-grade and G02's is inferred-strong-grade.
On the relationship to OAK-G02. G02 (Drainer-as-a-Service) and G05 (LockBit RaaS) share the commercial-service-with-affiliate-network operational model but differ along the target-class, attribution-grade, and value-per-incident axes. G02 affiliates execute many small-value individual-wallet phishing extractions; G05 affiliates execute few large-value enterprise-extortion intrusions. G02 attribution is wallet-cluster-and-industry-forensic-led and operates at inferred-strong; G05 attribution is sanctions-and-indictment-led and operates at confirmed. The two should not be conflated: a defender's anti-G02 controls (Permit2-signature warning lists, browser-extension-side phishing detection) are orthogonal to anti-G05 controls (enterprise-IT intrusion defense, ransom-payment counterparty screening).
On the relationship to OAK-G03. G03 (Russian laundering infrastructure, Garantex / Grinex / A7A5 lineage) is one of LockBit's documented downstream laundering venues, both at the affiliate-wallet level (per the SDN-listed addresses analysed in [chainalysis2024lockbit]) and at the operator-personal level (Khoroshev's documented Garantex transfers per [chainalysis2024khoroshev]). The G05 × G03 chain is the commercial-criminal-side analogue to the G01 × G03 chain documented in OAK-G03 via the Atomic Wallet example. Defenders running OAK-G03 watchlists should expect substantial overlap with G05-attributed inflows; defenders running G05 affiliate-cluster watchlists should expect substantial routing through G03-cluster venues. The two Groups are not the same threat actor but participate in a shared kill chain at high frequency.
On the relationship to OAK-G01. G01 and G05 are both upstream-extraction clusters with state-resident operating substrate (DPRK for G01, Russia for G05), but the operational model is fundamentally different: G01 is state-directed with bespoke wallet-and-laundering infrastructure under operator control; G05 is commercial-criminal with dependence on third-party laundering venues. The two clusters do not share infrastructure, do not collaborate operationally on the public record, and should not be co-clustered in defender models — they are listed in OAK as separate Groups precisely to keep this distinction explicit.
On v0.x evolution. G05's 2026+ trajectory will depend on (a) whether LockBit-branded extortion activity recovers from the post-Cronos volume collapse or whether the brand follows the Conti-2022 pattern of dispersal-into-successor-strains (Black Basta, Royal, Akira, and other Conti-successor brands); (b) whether Khoroshev or other named operators are apprehended and extradited (the $10M reward was active as of v0.1; Khoroshev remained at large in Russia); (c) whether further OFAC actions against G05's enabling infrastructure layer (Aeza-class hosting designations, additional affiliate designations) sustain the post-Cronos enforcement tempo; and (d) whether the post-Cronos collapse in LockBit market share is structural (the cluster is ending) or cyclical (the cluster is rebranding). OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates. Future OAK Group additions in the ransomware sector — Conti-successor brands, BlackCat / ALPHV (defunct after the March 2024 self-exit-scam), Cl0p, RansomHub — would each warrant their own OAK-Gnn entry rather than extension of G05, on the same per-cluster identity principle.