OAK — OnChain Attack Knowledge

Threat actor · OAK-G06

OAK-G06 — Evil Corp

Aliases
Evil Corp (the public name in OFAC, DOJ, NCA, FCDO, and DFAT designations from 2019 onward); the operational lineage variously tracked in industry reporting as Indrik Spider (CrowdStrike), TA505-adjacent (Proofpoint, with caveats — TA505 and Evil Corp are distinct clusters that have been confused in early reporting), UNC2165 (Mandiant, used specifically for the WastedLocker / Hades / Phoenix CryptoLocker / PayloadBIN / Macaw Locker post-2019 ransomware-rotation phase), the original "Jabber Zeus Crew" / "Business Club" Moscow circle from which the operation evolved circa 2007–2014, and the persona "aqua" / "aquamo" attached publicly to Maksim Viktorovich Yakubets per the December 2019 DOJ indictment. The named-defendant set across the December 2019 and October 2024 actions includes Maksim Viktorovich Yakubets (founder, principal), Igor Olegovich Turashev (administrator), Viktor Yakubets (Maksim's father), Artem Yakubets (Maksim's brother), Eduard Benderskiy (Maksim's father-in-law, former FSB Spetsnaz officer designated October 1, 2024 as the FSB-link node), and Aleksandr Viktorovich Ryzhenkov a.k.a. "Lizardking" (designated and indicted October 1, 2024 as Yakubets's deputy and as a LockBit affiliate operating under the handle "Beverley"). For OAK-G06 purposes the cluster is the Evil Corp operator family — the Yakubets-centred Russia-resident operator network plus the named-defendant set across the 2019 and 2024 actions — not any single malware strain in their portfolio.
First observed in crypto
approximately 2014 (Dridex banking-trojan operation began circa 2014 with cryptocurrency-wallet credential-theft modules added by approximately September 2016; ransomware-with-cryptocurrency-payments operation began with BitPaymer in 2017).
Attribution status
confirmed at the operator-and-named-defendant level — U.S. Treasury OFAC SDN designation of Evil Corp as an entity together with seventeen named individuals on December 5, 2019, pursuant to E.O. 13694 / E.O. 13757 ([ofac2019evilcorp]); same-day U.S. Department of Justice unsealed indictments in the Western District of Pennsylvania and the District of Nebraska charging Yakubets and Turashev with conspiracy, computer hacking, wire fraud, and bank fraud ([doj2019yakubets]); U.S. Department of State $5M reward for information leading to the arrest of Yakubets (the largest such reward for a cybercriminal at the time of issuance); coordinated trilateral sanctions architecture announced October 1, 2024 with U.S. Treasury OFAC, U.K. Foreign, Commonwealth and Development Office (FCDO) via the National Crime Agency, and Australia Department of Foreign Affairs and Trade (DFAT) jointly designating sixteen Evil Corp members and associates including Viktor Yakubets and Eduard Benderskiy as the FSB-link node ([ofac2024evilcorp], [nca2024evilcorp]); same-day U.S. DOJ unsealed seven-count indictment of Aleksandr Ryzhenkov in the Northern District of Texas explicitly naming the BitPaymer-and-LockBit-affiliate dual-track activity ([doj2024ryzhenkov]); explicit Treasury and NCA findings that Yakubets has provided material assistance to the Russian Federal Security Service (FSB) — the FSB-link finding was the December 2019 designation's stated rationale and was reinforced in the October 2024 designation through the Benderskiy nexus. Attribution that specific ransom-payment flows trace through specific downstream laundering venues (Garantex / OAK-G03, mixers, non-KYC exchanges) is inferred-strong from industry forensic providers (Chainalysis, TRM Labs) and from the U.K. NCA's October 2024 "Behind the Screens" publication ([chainalysisevilcorp2024], [trmevilcorp2024]).
Active
yes (degraded but operationally persistent as of v0.1) — the December 2019 sanctions produced a documented step-change in Evil Corp's operating model: ransomware-negotiation firms refused to process payments to Evil Corp-attributable wallets due to OFAC-violation exposure, which triggered a sustained brand-rotation cycle through WastedLocker (June 2020), Hades (December 2020), Phoenix CryptoLocker (2021), PayloadBIN (2021), Macaw Locker (2021), and ultimately a documented migration of senior operators including Ryzhenkov onto third-party RaaS platforms — most importantly LockBit (OAK-G05) — to "blend in" with the broader affiliate cohort and re-enable ransom collection from sanctions-cautious victims ([mandiantunc2165]). The October 2024 trilateral action and the public unmasking of Ryzhenkov as a LockBit affiliate explicitly closed the Evil-Corp-via-LockBit blend-in route. As of v0.1 publication, no named Evil Corp operator has been apprehended; all remained at large in Russia.

Description

OAK-G06 is the Evil Corp operator family: a Russia-resident, Yakubets-centred cybercriminal cluster that began as a Moscow-based credential-theft and money-mule operation circa 2007–2014 ("Jabber Zeus Crew" / "Business Club"), formalised under the Evil Corp brand around 2014, became the dominant operator of the Dridex banking trojan from approximately 2014 onward, pivoted into enterprise ransomware with BitPaymer in 2017, and entered a sustained sanctions-evasion brand-rotation cycle after the December 2019 OFAC designation. The DOJ-cited cumulative impact through 2019 was more than $100M in theft from hundreds of banks across more than 40 countries via Dridex; the NCA-cited cumulative impact through October 2024 was at least $300M in extortion from victims in healthcare, critical national infrastructure, government, and the private sector across Evil Corp's full operational lifetime. The cluster is genuinely distinct from the five prior OAK Groups: from OAK-G01 (Lazarus / DPRK) along the state-resident-criminal-with-FSB-tasking-vs-direct-state-actor axis (Evil Corp performs state work for the FSB on tasking but is not itself a state organ); from OAK-G02 (Drainer-as-a-Service) along the enterprise-extortion-and-banking-credential-theft-vs-individual-wallet-phishing axis and the named-operator-confirmed-vs-cluster-attribution-inferred axis; from OAK-G03 (Russian laundering infrastructure) along the upstream-extraction-vs-downstream-laundering axis (G06 generates illicit proceeds and is a documented G03 customer; G03 launders them); from OAK-G04 (DPRK IT-worker placement) along the cyber-extortion-and-banking-fraud-vs-employment-fraud axis and the Russia-vs-DPRK state axis; and from OAK-G05 (LockBit) along the named-persistent-operator-family-with-FSB-link-vs-RaaS-service-with-affiliate-network axis — with the v0.1-relevant subtlety that there is documented operational overlap between G05 and G06, since at least one senior Evil Corp operator (Ryzhenkov / "Beverley") executed LockBit-affiliate intrusions, but the two Groups remain distinct identities (G05 is the service operator; G06 is one of its highest-value affiliate sources during the post-2020 sanctions-evasion phase).

The operational model is a Russia-resident family-and-network commercial-criminal organisation with a documented FSB tasking relationship at the Yakubets-leadership level. Maksim Yakubets founded and directs the operation; Turashev served from approximately 2015 as Dridex administrator; Viktor Yakubets and Artem Yakubets participated as core members in a family-business model (the public NCA framing in October 2024 was "Mafia state" and "family-centred Moscow financial crime group"); Benderskiy, Maksim's father-in-law and a former FSB Spetsnaz officer, served as the FSB-link node and is the basis for the Treasury and NCA's documented finding that Evil Corp provides direct assistance to Russian state cyber operations (per the December 2019 OFAC designation, Yakubets was specifically tasked as of 2017 with acquiring confidential documents through cyber-enabled means and conducting cyber-enabled operations on the Russian state's behalf). Ryzhenkov served as Yakubets's deputy and was responsible for ransomware deployment at the operator-execution level; the October 2024 indictment alleges he personally executed at least 60 LockBit-encryptor builds and BitPaymer attacks against U.S. victims with cumulative ransom demands exceeding $100M.

The cluster's defender-relevant signature is named-Russia-resident-operator-family with FSB-tasking-and-OFAC-sanctions exposure, sustained brand-rotation across malware strains as the primary sanctions-evasion adaptation, and a documented migration into third-party RaaS affiliate roles (specifically LockBit / G05) once own-strain extortion became commercially infeasible under sanctions. Unlike OAK-G01 (which builds bespoke laundering chains under operator control) and unlike OAK-G05 (which depends on third-party laundering venues at the affiliate level), G06's defining commercial-side adaptation is upstream-malware-strain rotation rather than downstream-laundering-venue rotation — the post-2019 sequence Dridex → BitPaymer → WastedLocker → Hades → Phoenix CryptoLocker → PayloadBIN → Macaw Locker → LockBit-affiliate operation is the most extensively documented sanctions-driven brand-rotation history in the public ransomware record. This makes G06 the canonical worked example of sanctions-induced operator adaptation on the OAK Groups axis and the cleanest case in the framework where named-operator continuity is established forensically across multiple encryptor-strain rebrands.

Targeting profile

OAK-G06's victim profile is enterprise-IT and financial-sector rather than crypto-native, and the value-extraction layer runs through cryptocurrency for the ransomware portfolio and through traditional bank-fraud rails for the Dridex banking-trojan portfolio:

  • Banks and financial institutions (the Dridex portfolio's target class) — hundreds of banks in more than 40 countries per the December 2019 DOJ indictment and OFAC press release; Dridex's primary function is automated theft of online banking credentials and money-mule routing of proceeds.
  • Enterprise corporates across all sectors (the BitPaymer / WastedLocker / successor portfolio) — Garmin (the July 2020 WastedLocker incident, with widely-reported eight-figure ransom payment), the Norwegian newspaper Amedia, U.S. local-government and private-sector targets in the Ryzhenkov indictment's Northern-District-of-Texas victim set, and approximately 60 named victims in Ryzhenkov's LockBit-affiliate sub-portfolio.
  • U.K. health and public-sector institutions — explicitly cited in the U.K. FCDO October 2024 designation as a stated rationale ("Evil Corp has waged a campaign of destructive cyber-attacks worldwide for over a decade, including malware and ransomware attacks against UK health, government and public sector institutions").
  • Critical-infrastructure operators — present across the WastedLocker / Hades period; the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and FBI have published advisories covering Evil Corp tooling against critical-infrastructure sectors.
  • Cryptocurrency-industry firms as occasional targets — present but not the dominant target class; G06 is enterprise-extortion-and-banking-fraud-led rather than crypto-native-extraction-led.
  • Cryptocurrency-wallet end-users via Dridex credential-theft modules — Dridex acquired wallet-credential-theft features by approximately September 2016, expanding the malware's payout surface from bank-credential theft into cryptocurrency-wallet compromise; this is a secondary monetisation channel rather than the cluster's primary business line, but it is the channel that brings G06 into the on-chain-Tactic taxonomy at the credential-compromise step.
  • Downstream cryptocurrency users — only as secondary victims of the laundering rails the operation depends on (the load on Garantex and Russia-cluster non-KYC venues from G06 ransom-payment flows is part of the volume profile that produced the OAK-G03 sanctions cycle).

Observed Techniques

OAK v0.1's Tactic catalog is on-chain-extraction-focused; Evil Corp's intrusion surface (off-chain enterprise-IT compromise, banking-trojan credential theft, ransomware deployment) sits largely outside the on-chain Tactic scope and is documented via the conventional cyber-threat-intel taxonomy in the conventional cyber-threat-intel taxonomy. The on-chain Techniques observed in OAK-G06-attributable activity are concentrated on the credential-compromise and payment-and-laundering sides:

  • Wallet-credential-compromise via banking-trojan module — Dridex's post-2016 cryptocurrency-wallet credential-theft modules represent the on-chain entry point for G06; this Technique surface is structurally similar to commodity-infostealer-driven wallet compromise but with G06 it sits inside a long-running banking-trojan operation rather than a standalone infostealer service. v0.1 does not yet have a dedicated OAK-Tn.NNN for banking-trojan-driven wallet compromise; this is a TAXONOMY-GAPS.md candidate for v0.x.
  • OAK-T7.001 (Mixer-Routed Hop) — pre-2023 default for Evil Corp ransomware affiliates and operators routing extortion proceeds; usage declined in line with the sector-wide post-Tornado-Cash mixer-share decline ([ofac2022tornado], [chainalysis2024laundering]).
  • OAK-T7.002 (CEX Deposit-Address Layering) — the canonical post-2023 Evil-Corp-affiliate off-ramp, with Russia-cluster non-KYC venues and Garantex (OAK-G03) the named industry-forensic signatures ([chainalysisevilcorp2024], [trmevilcorp2024]).
  • OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by NCA, Chainalysis, TRM Labs, and Mandiant to maintain Evil-Corp-cluster identification across encryptor-strain rotations (Dridex → BitPaymer → WastedLocker → Hades → Phoenix CryptoLocker → PayloadBIN → Macaw Locker) and across the post-2022 LockBit-blend-in phase. The persistence of operator-cluster identity across this seven-plus encryptor-strain rotation is one of the cleanest worked examples of T8.001 in the public record and is what made the October 2024 Ryzhenkov attribution operationally tractable.
  • Adjacent / pre-incident vectors not in OAK v0.1 scope: off-chain initial access via phishing campaigns with malicious-macro attachments (the Dridex distribution baseline), software-vulnerability exploitation, and exposed-RDP exploitation; bank-fraud automation via money-mule networks routing fiat proceeds; and FSB-tasked espionage activity on the state-services-side of the operation. These are off-chain-IT-security-taxonomy and intel-services-side behaviours that shape G06's operational profile but sit outside the on-chain-Tactic taxonomy at v0.1.

Observed Examples

No public incidents at v0.1 — worked examples pending per-incident forensic publication.

  • December 2019 OFAC designation and DOJ indictments. OFAC designated Evil Corp as an entity plus seventeen named individuals on December 5, 2019 ([ofac2019evilcorp]); same-day DOJ unsealed indictments in WD Pennsylvania and D Nebraska against Yakubets and Turashev ([doj2019yakubets]); U.S. Department of State $5M reward issued for information leading to Yakubets's arrest. Treasury cited >$100M in Dridex-attributable theft from banks in >40 countries and explicitly cited Yakubets's FSB-tasking relationship as a designation rationale. Attribution at confirmed.
  • WastedLocker / Garmin incident (July 2020). Garmin suffered a multi-day global service outage attributed to a WastedLocker deployment; widely reported settlement of an eight-figure-USD ransom in cryptocurrency. The incident is the canonical worked example of the sanctions-evasion brand-rotation dynamic: the BitPaymer-to-WastedLocker transition was directly attributable in industry forensics to G06 despite the encryptor-strain change, but ransom-payment processing required negotiated workarounds because of the December 2019 OFAC exposure on Evil Corp. Attribution at inferred-strong at the per-incident level (industry-forensic-led; no public OFAC or DOJ press release on the Garmin incident specifically) and confirmed at the cluster-attribution level (the WastedLocker-to-Evil-Corp linkage is established in the October 2024 NCA "Behind the Screens" publication and [mandiantunc2165]).
  • UNC2165 to LockBit migration (documented June 2022). Mandiant publication "To HADES and Back" documenting the operational-tradecraft migration of UNC2165 (Evil Corp's post-2019 cluster identifier in Mandiant's taxonomy) onto the LockBit RaaS platform as a sanctions-evasion adaptation ([mandiantunc2165]). This is the canonical worked example of the G06-into-G05-affiliate-role dynamic and the public-record basis for the v0.1 OAK position that G05 and G06 are operationally overlapping but identity-distinct. Attribution at confirmed at the cluster-migration level via the October 2024 Ryzhenkov indictment.
  • October 2024 trilateral action and Ryzhenkov indictment. OFAC, FCDO/NCA, and DFAT jointly designated sixteen Evil Corp members and associates on October 1, 2024 ([ofac2024evilcorp], [nca2024evilcorp]); same-day U.S. DOJ unsealed seven-count indictment of Ryzhenkov in ND Texas explicitly naming the BitPaymer-and-LockBit-affiliate dual-track activity and citing >$100M in cumulative ransom demands across at least 60 LockBit attacks ([doj2024ryzhenkov]); same-day NCA published the "Evil Corp: Behind the Screens" eight-page operational profile ([nca2024evilcorp]). The October 2024 action is the cleanest single attribution event in the G06 record and the basis for the confirmed attribution status at the operator-and-named-defendant level. Attribution at confirmed.
  • Aggregate Evil Corp metrics from [ofac2019evilcorp] (>$100M from >hundreds of banks across >40 countries via Dridex through 2019) and from [nca2024evilcorp] (at least $300M in cumulative extortion across the operational lifetime through October 2024).
  • Worked examples for specific G06-mediated ransom-payment laundering flows are pending v0.x and will live under examples/ once the per-incident attribution surface stabilises sufficiently for the OAK confirmed / inferred-strong distinction.

Citations

  • [ofac2019evilcorp] — U.S. Treasury press release SM-845, December 5, 2019, designating Evil Corp as an entity together with seventeen named individuals including Maksim and Igor Turashev.
  • [doj2019yakubets] — U.S. Department of Justice unsealed indictments (WD Pennsylvania, D Nebraska), December 5, 2019, charging Yakubets and Turashev with conspiracy, computer hacking, wire fraud, and bank fraud.
  • [ofac2024evilcorp] — U.S. Treasury press release JY2623, October 1, 2024, designating sixteen Evil Corp members and associates in trilateral action with the U.K. and Australia.
  • [nca2024evilcorp] — U.K. National Crime Agency publication "Evil Corp: Behind the Screens," October 1, 2024, with U.K. FCDO designation announcement and the public unmasking of Aleksandr Ryzhenkov as a LockBit affiliate ("Beverley").
  • [doj2024ryzhenkov] — U.S. Department of Justice unsealed seven-count indictment of Aleksandr Viktorovich Ryzhenkov in ND Texas, October 1, 2024.
  • [chainalysisevilcorp2024] — Chainalysis forensic write-up of the October 2024 Evil Corp designation, brand-rotation history, and downstream laundering-flow analysis.
  • [trmevilcorp2024] — TRM Labs forensic write-up of the trilateral October 2024 Evil Corp action, with operator-cluster wallet attribution.
  • [mandiantunc2165] — Mandiant publication "To HADES and Back: UNC2165 Shifts to LOCKBIT to Evade Sanctions," June 2022, documenting the Evil Corp operational migration onto the LockBit RaaS platform as sanctions-evasion adaptation.
  • [chainalysis2024laundering] — broader laundering-route context (companion citation; cited from G01, G03, and G05 as well).
  • [ofac2022tornado] — sector-wide mixer-laundering enforcement context (referenced for the post-2022 ransomware-mixer-share decline, not for shared cluster identity).
  • [ofac2024khoroshev] — companion 2024 sanctions reference (cited from G05); shares the multi-jurisdiction sanctions-architecture framing OFAC and NCA used through 2024 against Russia-resident ransomware operators.

Discussion

On the attribution-strength split. The Evil Corp operator-and-named-defendant cluster is confirmed — the December 2019 OFAC entity-and-individual designation, the same-day DOJ indictments of Yakubets and Turashev, the State Department $5M reward, the trilateral October 2024 OFAC / FCDO / DFAT designation of sixteen members and associates, the same-day NCA "Behind the Screens" publication, and the same-day DOJ Ryzhenkov indictment together produce one of the cleanest sanctions-and-indictment attribution surfaces in the public record. By contrast, claims of the form "specific ransom payment X traces to specific Evil Corp operator Y at incident Z" are inferred-strong unless the specific operator is named in a court filing or OFAC designation; many tail-incident claims from industry forensics alone are inferred-strong only. OAK contributors writing G06-attributed examples should preserve this split per-incident, as with G03, G04, and G05.

On why OAK-G06 is operator-family rather than malware-strain. Naming this Group entry "Dridex" or "BitPaymer" or "WastedLocker" would have been the conventional external-framework framing but would mis-frame the operational continuity model. The malware portfolio has rotated extensively across strains (Dridex → BitPaymer → WastedLocker → Hades → Phoenix CryptoLocker → PayloadBIN → Macaw Locker → LockBit-affiliate operation under the LockBit codebase), explicitly as a sanctions-evasion adaptation; the operator-and-family-cluster (Yakubets-Turashev-Ryzhenkov-Benderskiy and the broader sixteen-named-defendant network) is a far cleaner persistent identity than any single strain. This is structurally the same logic OAK-G05 uses to choose RaaS-operation over encryptor-strain as the Group identity, but with G06 the case is sharper because the strain-rotation cadence is faster and is more clearly sanctions-driven rather than version-driven.

On the relationship to OAK-G05. G05 (LockBit RaaS) and G06 (Evil Corp) are operationally overlapping but identity-distinct: at least one senior Evil Corp operator (Ryzhenkov / "Beverley") executed approximately 60 LockBit-affiliate intrusions during the post-2020 sanctions-evasion phase, and the October 2024 NCA publication explicitly presents the Evil Corp / LockBit affiliate-overlap as a documented public-record finding. The correct OAK framing is that G06 used G05 as a service platform during a specific phase (June 2022 onward per Mandiant [mandiantunc2165]) without G05 and G06 becoming the same Group: G05 is the LockBit service operator (Khoroshev / LockBitSupp plus the affiliate-management infrastructure), and G06 is the Evil Corp operator family that supplied affiliates into G05's program among other channels. Defenders running G05 affiliate-cluster watchlists and G06 operator-family watchlists should expect substantial intersection on a defined post-2022 sub-cluster but should not collapse the two identities; the operational lifetimes are different (G06 since 2014, G05 since 2020), the leadership identities are different (Yakubets vs. Khoroshev), and the state-relationship structures are different (G06 has a documented FSB tasking relationship via Benderskiy; G05's state-relationship surface is less explicit in the public record).

On the relationship to OAK-G03. G03 (Russian laundering infrastructure, Garantex / Grinex / A7A5 lineage) is one of Evil Corp's documented downstream laundering venues, with the October 2024 trilateral action explicitly highlighting the Russia-cluster off-ramp dependency for Evil Corp ransom proceeds. The G06 × G03 chain is structurally parallel to the G05 × G03 chain documented in OAK-G05 and to the G01 × G03 chain documented in OAK-G03 via the Atomic Wallet example. Defenders running OAK-G03 watchlists should expect substantial overlap with G06-attributed inflows; defenders running G06 operator-family watchlists should expect substantial routing through G03-cluster venues. The two Groups are not the same threat actor but participate in a shared kill chain at high frequency, particularly during the post-2019 sanctions-evasion period when Russia-cluster non-KYC venues became operationally load-bearing for G06 ransom collection.

On the relationship to OAK-G01. G01 (Lazarus / DPRK) and G06 (Evil Corp) are both upstream-extraction clusters with state-resident operating substrate (DPRK for G01, Russia for G06) and both have documented state-tasking relationships at the leadership level. The operational models are nevertheless fundamentally different: G01 is state-directed with bespoke wallet-and-laundering infrastructure under operator control and crypto-native primary targeting (exchange hacks, DeFi exploits, supply-chain compromises against crypto-industry firms); G06 is commercial-criminal with FSB tasking layered on top, with enterprise-IT-and-banking-sector primary targeting and dependence on third-party laundering venues for ransom proceeds. The two clusters do not share infrastructure, do not collaborate operationally on the public record, and should not be co-clustered in defender models — they are listed in OAK as separate Groups precisely to keep the state-actor-vs-state-tolerated-criminal and crypto-native-vs-enterprise-IT distinctions explicit.

On the FSB-link finding and how it sits in OAK. Both the December 2019 OFAC designation and the October 2024 trilateral action made explicit findings that Evil Corp leadership has provided material assistance to the FSB and that the cluster operates with at least the tolerance and at most the active tasking of Russian state intelligence. OAK records this finding because it is part of the public attribution record and it informs threat-modelling expectations (the cluster is unlikely to be apprehended absent extraordinary diplomatic developments; the cluster's operational continuity is partially insulated from the commercial pressure that has degraded purely-criminal RaaS brands like LockBit). OAK does not re-classify G06 as a state actor on the basis of the FSB-link finding: the operational model is commercial-criminal, the targeting is mostly commercial, the monetisation is mostly extortion-and-bank-fraud, and the framing as a state actor would mis-frame the defender-relevant signature. The FSB link is a force-multiplier on a criminal cluster, not a re-classification of the cluster.

On v0.x evolution. G06's 2026+ trajectory will depend on (a) whether the post-October-2024 brand-rotation cycle produces further successor strains under different operator-affiliate compositions or whether the cluster has saturated the brand-rotation strategy and is increasingly reliant on third-party RaaS platforms (LockBit, post-LockBit successors, and other commercial RaaS); (b) whether any named Evil Corp operator is apprehended and extradited (none have been as of v0.1; all remain in Russia, which does not extradite its nationals); (c) whether further OFAC actions against G06's enabling infrastructure layer (laundering venues, hosting providers, money-mule networks) sustain the post-2024 enforcement tempo; (d) whether the FSB-tasking relationship intensifies under sustained Russia-state cyber-operational pressure; and (e) whether the G05 × G06 affiliate-overlap pattern documented in October 2024 generalises to other RaaS platforms post-LockBit. OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates.

Software used