OAK — OnChain Attack Knowledge

Threat actor · OAK-G10

OAK-G10 — ALPHV / BlackCat Ransomware-as-a-Service operation

Aliases
ALPHV (the operating brand on the Russian-language criminal-forum side, Nov 2021 — Mar 2024), BlackCat (the industry-default name derived from the leak-site icon and binary self-identification), Noberus (Symantec / Broadcom tracker name), and the affiliate cohort that overlapped with the Scattered Spider / UNC3944 / Octo Tempest / Muddled Libra social-engineering crew (named in subsequent DOJ indictments unsealed across 2024). For OAK-G10 purposes the cluster is the ALPHV/BlackCat RaaS operation — the core operator network behind the Rust-based ALPHV encryptor and its affiliate-management infrastructure, considered jointly with the Scattered-Spider-aligned affiliate stream that ran the highest-impact ALPHV intrusions of 2023 — not any single ALPHV-encryptor variant and not Scattered Spider as a standalone actor (Scattered Spider operated against multiple RaaS strains and warrants its own future OAK-Gnn entry on the same per-cluster identity principle that motivated splitting G07 from G01).
First observed in crypto
approximately November 2021 (ALPHV leak-site / RaaS-recruitment posts first observed on Russian-language criminal forums; the RaaS model with Bitcoin- and Monero-denominated ransom payments has been the operational default since inception, with Monero offered at a discount versus Bitcoin to reduce the operator-side laundering load).
Attribution status
confirmed at the operator-cluster-and-named-affiliate level — U.S. Federal Bureau of Investigation / Department of Justice disruption operation announced December 19, 2023, including FBI access to the ALPHV decryptor and a CISA / FBI joint advisory characterising the cluster's TTPs ([fbi2023blackcatdisruption], [cisa2023blackcatadvisory]); DOJ indictments unsealed across 2024 against multiple Scattered Spider members for the September 2023 MGM Resorts and Caesars Entertainment campaigns and earlier Reddit-targeting activity ([doj2024scatteredspider]); HHS / U.S. Department of Health and Human Services public advisories on the February 21, 2024 Change Healthcare incident ([hhs2024changehealthcare]); sustained multi-vendor industry-forensic corroboration (Mandiant, Microsoft, Sophos, SentinelOne, Recorded Future, Chainalysis, TRM Labs, Symantec) characterising the Rust-based encryptor lineage, the Russian-language operator-forum substrate, the affiliate-cut economics, and the February-to-March 2024 self-exit-scam dynamic. ALPHV itself was not OFAC-designated as a cluster within its operating window; that distinction makes G10 a confirmed-by-disruption-and-indictment rather than confirmed-by-OFAC-SDN-designation case at v0.1, which is operationally important for the asset-freeze counter-factual discussed below. Attribution that specific ransom-payment flows trace to specific affiliate wallets within the ALPHV cluster is inferred-strong from industry forensic providers; the canonical instance is the ~$22M Bitcoin payment from Change Healthcare that was traced on-chain by Chainalysis and TRM Labs to an affiliate wallet before the operator-side exit-scam diverted the funds out of affiliate control ([chainalysis2024alphvexit], [trm2024changehealthcare]).
Active
inactive as of v0.1 — the ALPHV-branded operation effectively ended on or around March 1–5, 2024 with the operator-side exit-scam shutdown: after the Change Healthcare ransom was paid in late February 2024, the ALPHV operator absconded with the affiliate's share of the proceeds, staged a fake "FBI seizure" banner on the ALPHV leak site (visibly distinguishable from the real Operation Cronos LockBit takedown banner), and shuttered the RaaS infrastructure. Per [chainalysis2025ransomware] and [trm2024changehealthcare], the affiliate ("Notchy") publicly accused the ALPHV operator on the RAMP forum of stealing the ~$22M Change Healthcare payment. Per multiple industry trackers, ALPHV-branded extortion activity ceased after early March 2024; affiliate continuity dispersed into successor RaaS strains (RansomHub being the most-cited successor brand for Notchy and overlapping affiliates), and the Scattered-Spider-aligned affiliate stream continued operating against other RaaS providers. OAK-G10 should be read as a closed cluster on the operator side and a dispersed cluster on the affiliate side, parallel to the Conti-2022 dispersal pattern.

Description

OAK-G10 is the ALPHV / BlackCat ransomware-as-a-service operation: a Russian-language operator network that, between November 2021 and the late-February-to-early-March 2024 exit-scam shutdown, was one of the three most prolific RaaS strains on the public record alongside OAK-G05 LockBit and the Conti-successor brand cohort. The cluster is genuinely distinct from the prior OAK Groups: from OAK-G05 LockBit along the tooling, affiliate-management style, and exit-dynamics axes despite shared Russian-language operator substrate; from OAK-G01 (Lazarus / DPRK direct attacks) and OAK-G07 (APT43 / Kimsuky) along the state-vs-commercial-criminal axis and the crypto-native-target-vs-enterprise-IT-target axis; from OAK-G02 (Drainer-as-a-Service) along the enterprise-extortion-vs-individual-wallet-phishing axis and the value-per-incident axis; and from OAK-G03 (Russian laundering infrastructure) along the upstream-extraction-vs-downstream-laundering axis. ALPHV's inclusion in OAK is not because it is a crypto-native operator — its targets are overwhelmingly traditional-enterprise IT estates, with healthcare, hospitality, and consumer-internet firms over-represented in the public victim record — but because cryptocurrency is the load-bearing payment-and-laundering rail of the entire RaaS business model, because the Change Healthcare exit-scam is the canonical worked example of the operator-vs-affiliate-asset-freeze counter-factual in the on-chain economy, and because the November 2023 SEC-Reporting-Disclosure tactic against MeridianLink is a tactical-novelty marker in the operator-pressure-tactic space that defenders, regulators, and exchanges should treat as a sustained behaviour pattern rather than a one-off.

The operational model is a textbook ransomware-as-a-service split with several operator-distinctive features. ALPHV was the first major ransomware family written in Rust — a tooling choice that produced cross-platform encryptor builds for Windows, Linux, and VMware ESXi from a shared codebase, complicated reverse-engineering and detection work for incident-response vendors during the cluster's first year of operation, and signalled the ransomware sector's broader 2022–2024 migration toward memory-safe systems languages. Affiliates received approximately 80–90% of the ransom-payment cut depending on negotiation tier (notably more affiliate-favourable than the LockBit ~80% / operator ~20% baseline), with payments routed to affiliate-controlled wallets under the operator's payment-and-negotiation-portal supervision. The operator persona ran the ALPHV leak site, the affiliate panel, the negotiation-chat infrastructure, and the Russian-language-forum recruitment posture; the affiliate cohort was unusually heterogeneous and included both Russian-speaking criminal-forum operators and the predominantly English-speaking Scattered Spider / UNC3944 social-engineering crew, whose September 2023 campaigns against MGM Resorts and Caesars Entertainment used voice-phishing of help-desk staff (rather than exploitation-of-public-facing-vulnerabilities) as the initial-access vector and made ALPHV the dominant RaaS brand in the Western press for a full quarter.

The cluster's defender-relevant signature is upstream-extraction-cluster with confirmed-grade public attribution at the disruption-and-indictment layer (rather than the OFAC-SDN layer), with a 2.5-year operating window terminated by an operator-side exit-scam rather than by law-enforcement seizure. Two cluster-distinctive operator behaviours warrant defender attention beyond the conventional RaaS-control set. First, the November 2023 SEC-filing pressure tactic against MeridianLink: ALPHV publicly filed a tip with the U.S. Securities and Exchange Commission complaining that MeridianLink had not made the four-business-day cyber-incident-reporting disclosure required under the SEC's then-new disclosure rule (which had not yet entered force at the time of the filing — a detail ALPHV either misjudged or accepted), accompanied by a screenshot of the SEC tip-submission portal posted to the ALPHV leak site. This was the first publicly-documented instance of a ransomware operator weaponising a securities-regulator disclosure regime as a victim-pressure mechanism, and it sits structurally outside any OAK on-chain Tactic — it is an operator-pressure-tactic novelty in the ransomware-extortion ecosystem rather than an on-chain Technique, and OAK contributors writing G10-attributed content should mark it as such. Second, the February-to-March 2024 exit-scam dynamic at Change Healthcare: after Optum / UnitedHealth Group's Change Healthcare subsidiary paid an approximately $22M Bitcoin ransom in late February 2024, the ALPHV operator (rather than the affiliate "Notchy" who ran the actual intrusion) re-routed the proceeds out of the affiliate's wallet, posted a fabricated FBI-seizure banner on the leak site, and shuttered the RaaS infrastructure. Per Chainalysis and TRM Labs forensic write-ups, the Change Healthcare payment was traced on-chain in close to real time by industry forensic providers; the counter-factual in which the proceeds had been frozen (e.g., via OFAC-SDN-listed-wallet enforcement at receiving deposit addresses, or via cooperation from a regulated CEX downstream of the affiliate's off-ramp chain) is the load-bearing case for the broader argument that real-time-traced ransomware payments to identified-but-non-OFAC-listed wallets are not, in practice, freezeable under v0.1 enforcement architecture. The exit-scam itself partitioned the Change Healthcare proceeds between the operator and Notchy, and the public-record reconstruction (per industry forensic providers) shows the operator-side share moving rapidly through laundering rails consistent with broader Russian-resident commercial-criminal off-ramp profiles, while Notchy's residual access to the original payment was disputed and incomplete.

Targeting profile

OAK-G10's victim profile is enterprise-IT rather than crypto-native, with sector concentration in healthcare, hospitality, retail, and consumer internet:

  • Healthcare-sector firms — Change Healthcare (Feb 2024, the canonical exit-scam case), Lehigh Valley Health Network (Feb 2023, the first publicly-named ALPHV healthcare victim with patient-imagery extortion as an aggravating factor), McLaren Health Care, NextGen Healthcare, and a long tail of hospital-system and clinical-network victims. Healthcare over-representation in the ALPHV record was a stated reason for the FBI / CISA December 2023 advisory tempo.
  • Hospitality and gaming-sector firms — MGM Resorts (Sep 2023), Caesars Entertainment (Sep 2023, with reported ransom payment); both attributed to the Scattered Spider / UNC3944 affiliate stream and both notable for the help-desk social-engineering initial-access vector.
  • Consumer-internet and software-sector firms — Reddit (Feb 2023 BlackCat-attributed source-code-and-documents disclosure threat following an earlier phishing-led intrusion; Reddit publicly stated it would not pay), Western Digital, NCR, MeridianLink (the November 2023 SEC-filing case).
  • Critical-infrastructure operators — energy-sector firms, manufacturing, defense-supplier-tier organisations; the U.S. CISA / FBI joint advisory of April 2022 (and update of December 2023) documents the cross-sector targeting profile.
  • Cryptocurrency-industry firms as occasional targets — present but not the dominant target class; G10 is enterprise-extortion-led, not crypto-native-extraction-led, and no ALPHV intrusion against a crypto-firm primary target reaches the public-record salience of any G01 incident.
  • Downstream cryptocurrency users — only as secondary victims of the laundering rails the operation depended on (the load on the Russian-language commercial-criminal off-ramp surface from G10 flows is part of the volume that produced the OAK-G03 sanctions cycle, though G10 was not as Garantex-concentrated as the G05 LockBit profile).

Observed Techniques

OAK v0.1's Tactic catalog is on-chain-extraction-focused; ALPHV's intrusion surface (off-chain enterprise IT compromise, including the Scattered-Spider-distinctive help-desk voice-phishing vector) sits outside that scope and is documented under external Group ID G1008 (BlackCat) and the Scattered Spider profile in the conventional cyber-threat-intel taxonomy. The on-chain Techniques observed in OAK-G10-attributable activity are concentrated on the payment-and-laundering side:

  • OAK-T7.001 (Mixer-Routed Hop) — observed as a partial / earlier-stage component of the broader ALPHV laundering chain, particularly for the Monero-denominated portion of ransom payments which routes through privacy-coin-conversion infrastructure rather than the Bitcoin mixer surface; usage of Bitcoin mixers for the BTC portion declined across 2023–2024 in step with the sector-wide decline driven by the OFAC Tornado Cash designation ([ofac2022tornado]) and the Sinbad takedown.
  • OAK-T7.002 (CEX Deposit-Address Layering) — the canonical post-2023 ALPHV-affiliate off-ramp for the Bitcoin portion of ransom payments, with affiliate-controlled deposit-address activity at non-KYC and lax-KYC venues a recurring industry-forensic signature; the Change Healthcare ~$22M payment was traced through this layering pattern in close to real time per [chainalysis2024alphvexit] and [trm2024changehealthcare].
  • OAK-T7.003 (Cross-Asset / Cross-Chain Laundering) — observed in the Change Healthcare exit-scam reconstruction as the operator-side off-ramp pattern after the proceeds were diverted from the affiliate wallet, including BTC-to-stablecoin and BTC-to-Monero conversion legs at the operator's downstream venues; the operator-vs-affiliate divergence in the laundering profile is itself a defender signal during a RaaS-operation's terminal-phase exit dynamic.
  • OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by Mandiant, Chainalysis, TRM Labs, and Recorded Future to maintain ALPHV affiliate-cluster identification across encryptor-version rotations, across the Scattered Spider / Russian-affiliate stream partition, and across the post-March-2024 affiliate-dispersal-into-RansomHub continuity. Distinguishing operator-side wallet activity from affiliate-side wallet activity during the Change Healthcare exit-scam window is the canonical worked case for T8.001 against a RaaS-terminal-phase event; the methodology generalises to other RaaS exit dynamics.
  • OAK-T8.002 (Operator-Persona Reuse) — observed in the affiliate-dispersal pattern after March 2024, with multiple ALPHV affiliates (notably Notchy) re-surfacing on RAMP and other Russian-language criminal forums under reused persona identifiers and known-cluster wallet-funder signatures; this is the operational-continuity attestation for the RansomHub-as-ALPHV-successor industry-forensic claim. Per [chainalysis2025ransomware] the cluster-continuity signal across the ALPHV-to-RansomHub transition is inferred-strong and is the basis for treating G10 as a closed-on-operator-side / dispersed-on-affiliate-side cluster rather than as fully extinct.
  • Adjacent / pre-incident vectors not in OAK v0.1 scope: off-chain initial access via help-desk voice-phishing (the Scattered Spider distinctive vector against MGM and Caesars), exposed-RDP and VPN exploitation, exploitation of public-facing vulnerabilities (including Microsoft Exchange ProxyShell-class and Veritas Backup Exec), and Active-Directory-trust-relationship abuse for ESXi-host targeting; these are the canonical ALPHV-affiliate intrusion vectors. They are off-chain-IT-security-taxonomy behaviours that shape G10's operational profile but sit outside the on-chain-Tactic taxonomy at v0.1.
  • Operator-pressure-tactic novelty not in OAK v0.1 scope: the November 2023 SEC-Reporting-Disclosure filing tactic against MeridianLink is a tactical novelty in the operator-pressure-tactic category that does not map cleanly onto any on-chain Tactic and is not a credible candidate for OAK-T inclusion at v0.1. It is documented here as an operator-behaviour evolution because (a) it is the first publicly-documented case of a ransomware operator weaponising a securities-regulator disclosure regime as a victim-pressure mechanism, (b) successor RaaS brands (RansomHub, Cl0p) have adopted variants of the regulator-and-press-disclosure pressure tactic, and (c) defender control-set design for ransomware response now needs to assume that regulator-disclosure leverage is part of the operator's negotiation toolkit.

Observed Examples

Worked examples in examples/:

The high-salience public-record events anchoring the cluster (narrative — see worked examples above for the canonical entries):

  • Operation BlackCat / FBI-led disruption (December 19, 2023). FBI public announcement of a months-long disruption operation that produced the ALPHV decryption tool (made available to victims), an FBI-controlled-takedown banner briefly displayed on the ALPHV leak site, and a CISA / FBI joint advisory updating the prior April-2022 advisory with current TTPs ([fbi2023blackcatdisruption], [cisa2023blackcatadvisory]). The operator subsequently re-asserted control of the leak-site infrastructure within hours and continued operating until the March 2024 exit-scam; the FBI-decryptor disclosure was the more durably-impactful component of the operation. Attribution at confirmed.
  • MGM Resorts and Caesars Entertainment intrusions (September 2023). Scattered Spider / UNC3944 affiliate-stream campaigns deploying the ALPHV encryptor, with help-desk voice-phishing as the initial-access vector. MGM publicly refused to pay and absorbed an estimated ~$100M in business-interruption costs; Caesars reported a paid ransom with a reduced disclosed-attack scope. Subsequently anchored multiple DOJ Scattered Spider indictments unsealed across 2024 ([doj2024scatteredspider]). Attribution at confirmed at the cluster-and-named-affiliate level.
  • Reddit data-extortion threat (February 2023). ALPHV-attributed claim of ~80GB of compressed source code and internal documents exfiltrated from Reddit via an earlier (February 5, 2023) phishing-led employee-credential compromise; Reddit publicly stated it would not pay. The case is notable as an early ALPHV brand-recognition event in the consumer-internet sector and as the precursor to the Scattered-Spider-aligned affiliate stream's later high-profile campaigns. Attribution at confirmed at the cluster level.
  • MeridianLink SEC-filing pressure tactic (November 15, 2023). ALPHV publicly filed a complaint with the SEC against MeridianLink alleging non-disclosure of a cyber-incident, accompanied by a screenshot of the SEC tip-submission portal posted to the ALPHV leak site ([reuters2023meridianlinksec], [bleepingcomputer2023meridianlinksec]). The first publicly-documented case of a ransomware operator weaponising a U.S. securities-regulator disclosure regime as a victim-pressure mechanism. Attribution at confirmed at the cluster level (the leak-site post is on the public record); attribution at the named-individual level is inferred-strong. Documented here as an operator-pressure-tactic novelty rather than an OAK on-chain Technique.
  • Change Healthcare ransomware incident and operator-side exit-scam (February 21 — March 5, 2024). Optum / UnitedHealth Group's Change Healthcare clearinghouse was encrypted by an ALPHV affiliate ("Notchy") on or around February 21, 2024; an approximately $22M Bitcoin payment was made in late February 2024 ([wired2024changehealthcareransom], [chainalysis2024alphvexit], [trm2024changehealthcare]); the ALPHV operator absconded with the affiliate's share of the proceeds and shuttered the leak site under a fabricated FBI-seizure banner around March 5, 2024; the affiliate publicly accused the operator on RAMP. The incident produced the largest healthcare-sector cyber-disruption event on the U.S. public record at the time, with Congressional testimony from UnitedHealth Group CEO Andrew Witty and HHS-led sectoral response ([hhs2024changehealthcare]). It is the canonical worked case in the public record for the real-time-traced-but-not-frozen ransomware-payment counter-factual: the proceeds were identified on-chain by industry forensic providers in close to real time, but were not subject to an OFAC-SDN-listed-wallet enforcement action because no ALPHV-cluster wallet held an SDN listing at the time of payment, and the operator-side off-ramp completed before any administrative-or-law-enforcement freeze could be staged. Attribution at confirmed at the cluster level; attribution of the operator-vs-affiliate proceeds split is inferred-strong per industry forensic reconstruction.
  • Aggregate ALPHV metrics from FBI / CISA reporting (~1,000 victim organisations across the cluster's lifetime per the December 2023 advisory; cluster ransom-payment volume across the 2.5-year window ranking ALPHV in the top three RaaS strains by volume per [chainalysis2025ransomware]); cluster-share of total ransomware payments fell sharply through Q2 2024 following the exit-scam, with successor-brand RansomHub absorbing a substantial fraction of the displaced affiliate volume.
  • Worked examples for specific G10-mediated ransom-payment laundering flows are pending v0.x and will live under examples/ once the per-incident attribution surface stabilises sufficiently for the OAK confirmed / inferred-strong distinction; the Change Healthcare case is the highest-priority candidate.

Citations

  • [fbi2023blackcatdisruption] — U.S. FBI / DOJ announcement of the BlackCat / ALPHV disruption operation, December 19, 2023; FBI-issued decryption tool.
  • [cisa2023blackcatadvisory] — Joint CISA / FBI / HHS cyber-security advisory on BlackCat / ALPHV TTPs, December 2023 update of the April 2022 advisory.
  • [doj2024scatteredspider] — U.S. DOJ indictments unsealed across 2024 against Scattered Spider / UNC3944 members for the MGM Resorts, Caesars Entertainment, and Reddit-class campaigns.
  • [hhs2024changehealthcare] — U.S. Department of Health and Human Services public advisory on the Change Healthcare incident and HPH-sector response, 2024.
  • [chainalysis2024alphvexit] — Chainalysis forensic write-up of the ALPHV / BlackCat exit-scam and Change Healthcare ~$22M Bitcoin ransom-payment tracing, 2024.
  • [trm2024changehealthcare] — TRM Labs forensic write-up of the Change Healthcare ransom payment, on-chain tracing and operator-vs-affiliate divergence, 2024.
  • [chainalysis2025ransomware] — Chainalysis 2024-recap ransomware report (referenced from G05 as well); documents the post-exit-scam ALPHV volume collapse and the RansomHub-successor affiliate-dispersal pattern.
  • [reuters2023meridianlinksec] — Reuters reporting on the November 15, 2023 ALPHV SEC-filing pressure tactic against MeridianLink.
  • [bleepingcomputer2023meridianlinksec] — BleepingComputer reporting on the MeridianLink SEC-filing tactic, including the leak-site screenshot of the SEC tip-submission portal.
  • [wired2024changehealthcareransom] — Wired reporting on the Change Healthcare ~$22M Bitcoin ransom payment, February 2024.
  • [ofac2022tornado] — sector-wide mixer-laundering enforcement context (referenced for the post-2022 ransomware-mixer-share decline, not for shared cluster identity).

Discussion

On the attribution-strength split. The ALPHV / BlackCat operator-cluster attribution is confirmed at the disruption-and-indictment layer — coordinated FBI / CISA / HHS public actions in December 2023, multiple Scattered Spider DOJ indictments across 2024, sustained multi-vendor industry-forensic corroboration — but is not OFAC-SDN-confirmed at the cluster level. ALPHV and its named affiliates were not OFAC-designated within the cluster's operating window. This is operationally important: the Change Healthcare ransom payment in February 2024 was traced in close to real time but was not freezable under v0.1 enforcement architecture, because no ALPHV-cluster wallet held an SDN listing. Compared to OAK-G05 LockBit (where Operation Cronos produced same-day SDN designations of two named affiliates and ten cryptocurrency-address SDN identifiers), G10 is the adjacent counter-factual: a closely-comparable Russian-language RaaS cluster that ran for 2.5 years, paid out an order of $100M-or-more in extortion proceeds, and exited via operator-side scam rather than law-enforcement seizure precisely because the OFAC-SDN architecture never caught up with it. OAK contributors writing G10-attributed examples should preserve this attribution-strength split per-incident, and should not infer OFAC-style asset-freeze-readiness from the underlying confirmed-grade cluster attribution.

On why OAK-G10 is RaaS-operation rather than individual-affiliate and not encryptor-strain. Naming this Group entry "ALPHV encryptor" or "BlackCat ransomware family" would have been the conventional external-framework framing (ALPHV is tracked under external Software ID S1068 and external Group ID G1008), but would mis-frame the operational continuity model in the same way that the analogous framing would mis-frame OAK-G05. The Rust-based ALPHV encryptor codebase rotated across versions, partial source code was leaked or recovered through industry tooling, and the post-exit-scam affiliate dispersal carried operational continuity into successor-brand RaaS strains rather than into ALPHV-codebase forks; the operator-and-affiliate-cluster is a cleaner persistent identity than the strain. By the same logic, naming the Group at the individual-affiliate level (Notchy, the Scattered Spider members named in DOJ indictments) would mis-frame the service-layer-persistence pattern that defines RaaS operationally. OAK-G10 sits at the same level of abstraction as OAK-G05 (LockBit RaaS) and OAK-G02 (Drainer-as-a-Service), with the difference that G10's per-named-operator attribution is confirmed-by-disruption-and-indictment-grade rather than confirmed-by-OFAC-SDN-designation-grade.

On the relationship to OAK-G05 (cluster boundary). G05 (LockBit) and G10 (ALPHV / BlackCat) share Russian-language operator substrate, operate the same RaaS business model, and overlap in affiliate cohorts (multiple criminal-forum operators ran intrusions against both LockBit and ALPHV depending on negotiated cuts and operational availability). They differ along four cluster-boundary axes: (1) Tooling: LockBit's encryptor lineage is C++-and-assembly-rooted (with a 2024 LockBit-NG-Dev pre-release the first significant tooling-architecture pivot); ALPHV was the first major Rust-based RaaS strain, with cross-platform Windows/Linux/ESXi builds from a shared codebase. (2) Affiliate-management style: LockBit ran a more centralised affiliate panel under a single principal operator (LockBitSupp / Khoroshev) with documented disciplinary actions against affiliates who violated cluster norms; ALPHV ran a more affiliate-favourable economic split (~80–90% to affiliates versus LockBit's ~80%) and a more heterogeneous affiliate cohort spanning Russian-speaking and English-speaking operators including the Scattered Spider crew. (3) Exit dynamics: LockBit was disrupted by coordinated multinational law enforcement (Operation Cronos, February 2024) with same-day OFAC designations of named affiliates; ALPHV exited via operator-side scam (March 2024) with no OFAC designation at the cluster level. (4) Public-attribution surface: LockBit produced a confirmed-by-OFAC-SDN-designation cluster (with named-defendant indictments and ten SDN-listed cryptocurrency addresses); ALPHV produced a confirmed-by-disruption-and-indictment cluster without OFAC-SDN-listed cryptocurrency addresses. The two clusters should not be conflated: a defender's anti-G05 watchlist surface (the ten OFAC-SDN-listed addresses, the Garantex-concentrated downstream rail) is structurally different from a defender's anti-G10 watchlist surface (industry-forensic-only, no SDN anchor, more diversified downstream rail).

On the relationship to OAK-G03. G03 (Russian laundering infrastructure, Garantex / Grinex / A7A5 lineage) was a documented downstream venue for some fraction of ALPHV proceeds, but the G10 / G03 chain is less concentrated than the G05 / G03 chain. ALPHV's affiliate cohort was more heterogeneous and the operator-side off-ramp profile in the Change Healthcare exit-scam shows broader laundering-rail distribution than the LockBit profile shows. Defenders running OAK-G03 watchlists should expect some overlap with G10-attributed inflows but should not expect the dense overlap they would expect with G05-attributed inflows.

On the SEC-filing tactic as operator-behaviour evolution rather than on-chain Technique. The November 2023 MeridianLink SEC-filing case is a tactical-novelty marker that defender control-set design needs to internalise even though it is not an OAK-T-classifiable on-chain Technique. The operator-pressure-tactic surface in ransomware extortion has expanded across 2023–2025 from leak-site naming-and-shaming to victim-customer / victim-employee outreach, regulator-disclosure-regime weaponisation (the SEC-filing tactic and its successors at RansomHub and Cl0p), and selective press-disclosure leverage. OAK should not absorb operator-pressure-tactic novelty into its on-chain Tactic catalog at v0.1 — it would dilute the on-chain framing — but G10's documentation should preserve the marker for downstream consumers building incident-response runbooks. The defender takeaway is that ransomware negotiation in 2024-and-after operates under a substantively different disclosure-regime threat model than it did in 2022, and counter-party-screening control sets need to assume that operator pressure on the regulator-disclosure surface is part of the negotiation environment.

On the exit-scam dynamic and the asset-freeze counter-factual. The Change Healthcare case is the canonical worked example, on the public record, of the real-time-traced ransomware payment that was not frozen. Industry forensic providers traced the ~$22M Bitcoin payment within hours of confirmation; the operator-side exit-scam off-ramped a substantial fraction of those proceeds within days; no OFAC-SDN-listed-wallet enforcement action was available, because no ALPHV-cluster wallet held an SDN listing at the time. This is the load-bearing counter-factual for the broader argument that on-chain visibility is necessary but not sufficient for ransomware-payment recovery — enforcement reach (administrative SDN designations on receiving wallets, regulated-CEX cooperation downstream, Tornado-Cash-class designations on intermediating infrastructure) is the binding constraint. Compared to G05 LockBit, where same-day OFAC SDN designations of ten cryptocurrency addresses produced a partial freeze surface against affiliate-controlled flows, G10 produced no freeze surface despite confirmed-grade attribution at every layer except the OFAC-SDN-designation layer. The lesson for v0.x OAK content and for downstream defenders / regulators / exchanges is that attribution without designation does not produce a freeze, and that the public-policy interval between cluster-attribution and SDN-designation is itself a material exposure window during which traced proceeds can off-ramp under the operator's full control.

On the affiliate-vs-operator divergence. The Change Healthcare exit-scam is also the canonical case where the affiliate-vs-operator partition of RaaS proceeds becomes operationally visible on-chain. Notchy (the affiliate) ran the intrusion and was contractually due the affiliate-cut share of the $22M payment; the ALPHV operator absconded with that share and posted a fabricated FBI-seizure banner. Industry forensic reconstruction shows the operator-side flow taking a different downstream path than the affiliate-side residual flow. This partition matters for defender attribution because it shows that cluster-level wallet attribution is not the same as principal-level wallet attribution within a cluster; the OAK-T8.001 (Common-Funder Cluster Reuse) attribution-side Technique can identify the cluster but does not partition operator-from-affiliate within it without additional signal (forum-disclosure of the dispute, operator-persona reuse on successor brands, downstream-venue concentration). G10's documentation preserves this distinction explicitly, and OAK contributors writing G10-attributed examples should mark whether each on-chain flow is operator-side, affiliate-side, or unresolved.

On v0.x evolution. G10's 2026+ trajectory will depend on (a) whether further DOJ Scattered Spider indictments and successor-brand (RansomHub, Cl0p, Akira) attributions extend the cluster-continuity attestation, (b) whether OFAC retroactively designates ALPHV-cluster wallets — possible but not highly probable, given the cluster's terminal-phase status and the tendency of OFAC enforcement to concentrate on still-active operators — (c) whether a worked example of the Change Healthcare incident is added under examples/ once the per-flow attribution surface stabilises sufficiently, and (d) whether the operator-pressure-tactic novelty surface produces sufficient successor-brand instances to warrant a dedicated v0.x OAK Tactic for regulator-disclosure-regime weaponisation outside the on-chain framing. OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates. Future OAK Group additions in the ransomware sector — Conti-successor brands, RansomHub as a standalone successor-brand entry, Cl0p, Scattered Spider as a multi-RaaS-affiliate cluster in its own right — would each warrant their own OAK-Gnn entry rather than extension of G05 or G10, on the same per-cluster identity principle.

Software used