Threat actor · OAK-G10
OAK-G10 — ALPHV / BlackCat Ransomware-as-a-Service operation
Description
OAK-G10 is the ALPHV / BlackCat ransomware-as-a-service operation: a Russian-language operator network that, between November 2021 and the late-February-to-early-March 2024 exit-scam shutdown, was one of the three most prolific RaaS strains on the public record alongside OAK-G05 LockBit and the Conti-successor brand cohort. The cluster is genuinely distinct from the prior OAK Groups: from OAK-G05 LockBit along the tooling, affiliate-management style, and exit-dynamics axes despite shared Russian-language operator substrate; from OAK-G01 (Lazarus / DPRK direct attacks) and OAK-G07 (APT43 / Kimsuky) along the state-vs-commercial-criminal axis and the crypto-native-target-vs-enterprise-IT-target axis; from OAK-G02 (Drainer-as-a-Service) along the enterprise-extortion-vs-individual-wallet-phishing axis and the value-per-incident axis; and from OAK-G03 (Russian laundering infrastructure) along the upstream-extraction-vs-downstream-laundering axis. ALPHV's inclusion in OAK is not because it is a crypto-native operator — its targets are overwhelmingly traditional-enterprise IT estates, with healthcare, hospitality, and consumer-internet firms over-represented in the public victim record — but because cryptocurrency is the load-bearing payment-and-laundering rail of the entire RaaS business model, because the Change Healthcare exit-scam is the canonical worked example of the operator-vs-affiliate-asset-freeze counter-factual in the on-chain economy, and because the November 2023 SEC-Reporting-Disclosure tactic against MeridianLink is a tactical-novelty marker in the operator-pressure-tactic space that defenders, regulators, and exchanges should treat as a sustained behaviour pattern rather than a one-off.
The operational model is a textbook ransomware-as-a-service split with several operator-distinctive features. ALPHV was the first major ransomware family written in Rust — a tooling choice that produced cross-platform encryptor builds for Windows, Linux, and VMware ESXi from a shared codebase, complicated reverse-engineering and detection work for incident-response vendors during the cluster's first year of operation, and signalled the ransomware sector's broader 2022–2024 migration toward memory-safe systems languages. Affiliates received approximately 80–90% of the ransom-payment cut depending on negotiation tier (notably more affiliate-favourable than the LockBit ~80% / operator ~20% baseline), with payments routed to affiliate-controlled wallets under the operator's payment-and-negotiation-portal supervision. The operator persona ran the ALPHV leak site, the affiliate panel, the negotiation-chat infrastructure, and the Russian-language-forum recruitment posture; the affiliate cohort was unusually heterogeneous and included both Russian-speaking criminal-forum operators and the predominantly English-speaking Scattered Spider / UNC3944 social-engineering crew, whose September 2023 campaigns against MGM Resorts and Caesars Entertainment used voice-phishing of help-desk staff (rather than exploitation-of-public-facing-vulnerabilities) as the initial-access vector and made ALPHV the dominant RaaS brand in the Western press for a full quarter.
The cluster's defender-relevant signature is upstream-extraction-cluster with confirmed-grade public attribution at the disruption-and-indictment layer (rather than the OFAC-SDN layer), with a 2.5-year operating window terminated by an operator-side exit-scam rather than by law-enforcement seizure. Two cluster-distinctive operator behaviours warrant defender attention beyond the conventional RaaS-control set. First, the November 2023 SEC-filing pressure tactic against MeridianLink: ALPHV publicly filed a tip with the U.S. Securities and Exchange Commission complaining that MeridianLink had not made the four-business-day cyber-incident-reporting disclosure required under the SEC's then-new disclosure rule (which had not yet entered force at the time of the filing — a detail ALPHV either misjudged or accepted), accompanied by a screenshot of the SEC tip-submission portal posted to the ALPHV leak site. This was the first publicly-documented instance of a ransomware operator weaponising a securities-regulator disclosure regime as a victim-pressure mechanism, and it sits structurally outside any OAK on-chain Tactic — it is an operator-pressure-tactic novelty in the ransomware-extortion ecosystem rather than an on-chain Technique, and OAK contributors writing G10-attributed content should mark it as such. Second, the February-to-March 2024 exit-scam dynamic at Change Healthcare: after Optum / UnitedHealth Group's Change Healthcare subsidiary paid an approximately $22M Bitcoin ransom in late February 2024, the ALPHV operator (rather than the affiliate "Notchy" who ran the actual intrusion) re-routed the proceeds out of the affiliate's wallet, posted a fabricated FBI-seizure banner on the leak site, and shuttered the RaaS infrastructure. Per Chainalysis and TRM Labs forensic write-ups, the Change Healthcare payment was traced on-chain in close to real time by industry forensic providers; the counter-factual in which the proceeds had been frozen (e.g., via OFAC-SDN-listed-wallet enforcement at receiving deposit addresses, or via cooperation from a regulated CEX downstream of the affiliate's off-ramp chain) is the load-bearing case for the broader argument that real-time-traced ransomware payments to identified-but-non-OFAC-listed wallets are not, in practice, freezeable under v0.1 enforcement architecture. The exit-scam itself partitioned the Change Healthcare proceeds between the operator and Notchy, and the public-record reconstruction (per industry forensic providers) shows the operator-side share moving rapidly through laundering rails consistent with broader Russian-resident commercial-criminal off-ramp profiles, while Notchy's residual access to the original payment was disputed and incomplete.
Targeting profile
OAK-G10's victim profile is enterprise-IT rather than crypto-native, with sector concentration in healthcare, hospitality, retail, and consumer internet:
- Healthcare-sector firms — Change Healthcare (Feb 2024, the canonical exit-scam case), Lehigh Valley Health Network (Feb 2023, the first publicly-named ALPHV healthcare victim with patient-imagery extortion as an aggravating factor), McLaren Health Care, NextGen Healthcare, and a long tail of hospital-system and clinical-network victims. Healthcare over-representation in the ALPHV record was a stated reason for the FBI / CISA December 2023 advisory tempo.
- Hospitality and gaming-sector firms — MGM Resorts (Sep 2023), Caesars Entertainment (Sep 2023, with reported ransom payment); both attributed to the Scattered Spider / UNC3944 affiliate stream and both notable for the help-desk social-engineering initial-access vector.
- Consumer-internet and software-sector firms — Reddit (Feb 2023 BlackCat-attributed source-code-and-documents disclosure threat following an earlier phishing-led intrusion; Reddit publicly stated it would not pay), Western Digital, NCR, MeridianLink (the November 2023 SEC-filing case).
- Critical-infrastructure operators — energy-sector firms, manufacturing, defense-supplier-tier organisations; the U.S. CISA / FBI joint advisory of April 2022 (and update of December 2023) documents the cross-sector targeting profile.
- Cryptocurrency-industry firms as occasional targets — present but not the dominant target class; G10 is enterprise-extortion-led, not crypto-native-extraction-led, and no ALPHV intrusion against a crypto-firm primary target reaches the public-record salience of any G01 incident.
- Downstream cryptocurrency users — only as secondary victims of the laundering rails the operation depended on (the load on the Russian-language commercial-criminal off-ramp surface from G10 flows is part of the volume that produced the OAK-G03 sanctions cycle, though G10 was not as Garantex-concentrated as the G05 LockBit profile).
Observed Techniques
OAK v0.1's Tactic catalog is on-chain-extraction-focused; ALPHV's intrusion surface (off-chain enterprise IT compromise, including the Scattered-Spider-distinctive help-desk voice-phishing vector) sits outside that scope and is documented under external Group ID G1008 (BlackCat) and the Scattered Spider profile in the conventional cyber-threat-intel taxonomy. The on-chain Techniques observed in OAK-G10-attributable activity are concentrated on the payment-and-laundering side:
- OAK-T7.001 (Mixer-Routed Hop) — observed as a partial / earlier-stage component of the broader ALPHV laundering chain, particularly for the Monero-denominated portion of ransom payments which routes through privacy-coin-conversion infrastructure rather than the Bitcoin mixer surface; usage of Bitcoin mixers for the BTC portion declined across 2023–2024 in step with the sector-wide decline driven by the OFAC Tornado Cash designation (
[ofac2022tornado]) and the Sinbad takedown. - OAK-T7.002 (CEX Deposit-Address Layering) — the canonical post-2023 ALPHV-affiliate off-ramp for the Bitcoin portion of ransom payments, with affiliate-controlled deposit-address activity at non-KYC and lax-KYC venues a recurring industry-forensic signature; the Change Healthcare ~$22M payment was traced through this layering pattern in close to real time per
[chainalysis2024alphvexit]and[trm2024changehealthcare]. - OAK-T7.003 (Cross-Asset / Cross-Chain Laundering) — observed in the Change Healthcare exit-scam reconstruction as the operator-side off-ramp pattern after the proceeds were diverted from the affiliate wallet, including BTC-to-stablecoin and BTC-to-Monero conversion legs at the operator's downstream venues; the operator-vs-affiliate divergence in the laundering profile is itself a defender signal during a RaaS-operation's terminal-phase exit dynamic.
- OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by Mandiant, Chainalysis, TRM Labs, and Recorded Future to maintain ALPHV affiliate-cluster identification across encryptor-version rotations, across the Scattered Spider / Russian-affiliate stream partition, and across the post-March-2024 affiliate-dispersal-into-RansomHub continuity. Distinguishing operator-side wallet activity from affiliate-side wallet activity during the Change Healthcare exit-scam window is the canonical worked case for T8.001 against a RaaS-terminal-phase event; the methodology generalises to other RaaS exit dynamics.
- OAK-T8.002 (Operator-Persona Reuse) — observed in the affiliate-dispersal pattern after March 2024, with multiple ALPHV affiliates (notably Notchy) re-surfacing on RAMP and other Russian-language criminal forums under reused persona identifiers and known-cluster wallet-funder signatures; this is the operational-continuity attestation for the RansomHub-as-ALPHV-successor industry-forensic claim. Per
[chainalysis2025ransomware]the cluster-continuity signal across the ALPHV-to-RansomHub transition is inferred-strong and is the basis for treating G10 as a closed-on-operator-side / dispersed-on-affiliate-side cluster rather than as fully extinct. - Adjacent / pre-incident vectors not in OAK v0.1 scope: off-chain initial access via help-desk voice-phishing (the Scattered Spider distinctive vector against MGM and Caesars), exposed-RDP and VPN exploitation, exploitation of public-facing vulnerabilities (including Microsoft Exchange ProxyShell-class and Veritas Backup Exec), and Active-Directory-trust-relationship abuse for ESXi-host targeting; these are the canonical ALPHV-affiliate intrusion vectors. They are off-chain-IT-security-taxonomy behaviours that shape G10's operational profile but sit outside the on-chain-Tactic taxonomy at v0.1.
- Operator-pressure-tactic novelty not in OAK v0.1 scope: the November 2023 SEC-Reporting-Disclosure filing tactic against MeridianLink is a tactical novelty in the operator-pressure-tactic category that does not map cleanly onto any on-chain Tactic and is not a credible candidate for OAK-T inclusion at v0.1. It is documented here as an operator-behaviour evolution because (a) it is the first publicly-documented case of a ransomware operator weaponising a securities-regulator disclosure regime as a victim-pressure mechanism, (b) successor RaaS brands (RansomHub, Cl0p) have adopted variants of the regulator-and-press-disclosure pressure tactic, and (c) defender control-set design for ransomware response now needs to assume that regulator-disclosure leverage is part of the operator's negotiation toolkit.
Observed Examples
Worked examples in examples/:
examples/2023-09-mgm-resorts.md— MGM Resorts ALPHV-encryptor intrusion via Scattered Spider help-desk voice-phishing; ~$100M business-interruption cost; payment refused.examples/2023-09-caesars-entertainment.md— Caesars Entertainment paid-ransom case (~$15M) via the same Scattered Spider × ALPHV affiliate stream.examples/2024-02-change-healthcare-ransom.md— Optum / UnitedHealth Change Healthcare clearinghouse encryption + ~$22M Bitcoin ransom payment.examples/2024-04-change-healthcare-reextortion.md— RansomHub-attributed re-extortion against the same victim using the data exfiltrated during the ALPHV affiliate's intrusion; canonical example of the post-exit-scam affiliate-dispersal pattern.
The high-salience public-record events anchoring the cluster (narrative — see worked examples above for the canonical entries):
- Operation BlackCat / FBI-led disruption (December 19, 2023). FBI public announcement of a months-long disruption operation that produced the ALPHV decryption tool (made available to victims), an FBI-controlled-takedown banner briefly displayed on the ALPHV leak site, and a CISA / FBI joint advisory updating the prior April-2022 advisory with current TTPs (
[fbi2023blackcatdisruption],[cisa2023blackcatadvisory]). The operator subsequently re-asserted control of the leak-site infrastructure within hours and continued operating until the March 2024 exit-scam; the FBI-decryptor disclosure was the more durably-impactful component of the operation. Attribution at confirmed. - MGM Resorts and Caesars Entertainment intrusions (September 2023). Scattered Spider / UNC3944 affiliate-stream campaigns deploying the ALPHV encryptor, with help-desk voice-phishing as the initial-access vector. MGM publicly refused to pay and absorbed an estimated ~$100M in business-interruption costs; Caesars reported a paid ransom with a reduced disclosed-attack scope. Subsequently anchored multiple DOJ Scattered Spider indictments unsealed across 2024 (
[doj2024scatteredspider]). Attribution at confirmed at the cluster-and-named-affiliate level. - Reddit data-extortion threat (February 2023). ALPHV-attributed claim of ~80GB of compressed source code and internal documents exfiltrated from Reddit via an earlier (February 5, 2023) phishing-led employee-credential compromise; Reddit publicly stated it would not pay. The case is notable as an early ALPHV brand-recognition event in the consumer-internet sector and as the precursor to the Scattered-Spider-aligned affiliate stream's later high-profile campaigns. Attribution at confirmed at the cluster level.
- MeridianLink SEC-filing pressure tactic (November 15, 2023). ALPHV publicly filed a complaint with the SEC against MeridianLink alleging non-disclosure of a cyber-incident, accompanied by a screenshot of the SEC tip-submission portal posted to the ALPHV leak site (
[reuters2023meridianlinksec],[bleepingcomputer2023meridianlinksec]). The first publicly-documented case of a ransomware operator weaponising a U.S. securities-regulator disclosure regime as a victim-pressure mechanism. Attribution at confirmed at the cluster level (the leak-site post is on the public record); attribution at the named-individual level is inferred-strong. Documented here as an operator-pressure-tactic novelty rather than an OAK on-chain Technique. - Change Healthcare ransomware incident and operator-side exit-scam (February 21 — March 5, 2024). Optum / UnitedHealth Group's Change Healthcare clearinghouse was encrypted by an ALPHV affiliate ("Notchy") on or around February 21, 2024; an approximately $22M Bitcoin payment was made in late February 2024 (
[wired2024changehealthcareransom],[chainalysis2024alphvexit],[trm2024changehealthcare]); the ALPHV operator absconded with the affiliate's share of the proceeds and shuttered the leak site under a fabricated FBI-seizure banner around March 5, 2024; the affiliate publicly accused the operator on RAMP. The incident produced the largest healthcare-sector cyber-disruption event on the U.S. public record at the time, with Congressional testimony from UnitedHealth Group CEO Andrew Witty and HHS-led sectoral response ([hhs2024changehealthcare]). It is the canonical worked case in the public record for the real-time-traced-but-not-frozen ransomware-payment counter-factual: the proceeds were identified on-chain by industry forensic providers in close to real time, but were not subject to an OFAC-SDN-listed-wallet enforcement action because no ALPHV-cluster wallet held an SDN listing at the time of payment, and the operator-side off-ramp completed before any administrative-or-law-enforcement freeze could be staged. Attribution at confirmed at the cluster level; attribution of the operator-vs-affiliate proceeds split is inferred-strong per industry forensic reconstruction. - Aggregate ALPHV metrics from FBI / CISA reporting (~1,000 victim organisations across the cluster's lifetime per the December 2023 advisory; cluster ransom-payment volume across the 2.5-year window ranking ALPHV in the top three RaaS strains by volume per
[chainalysis2025ransomware]); cluster-share of total ransomware payments fell sharply through Q2 2024 following the exit-scam, with successor-brand RansomHub absorbing a substantial fraction of the displaced affiliate volume. - Worked examples for specific G10-mediated ransom-payment laundering flows are pending v0.x and will live under
examples/once the per-incident attribution surface stabilises sufficiently for the OAK confirmed / inferred-strong distinction; the Change Healthcare case is the highest-priority candidate.
Citations
[fbi2023blackcatdisruption]— U.S. FBI / DOJ announcement of the BlackCat / ALPHV disruption operation, December 19, 2023; FBI-issued decryption tool.[cisa2023blackcatadvisory]— Joint CISA / FBI / HHS cyber-security advisory on BlackCat / ALPHV TTPs, December 2023 update of the April 2022 advisory.[doj2024scatteredspider]— U.S. DOJ indictments unsealed across 2024 against Scattered Spider / UNC3944 members for the MGM Resorts, Caesars Entertainment, and Reddit-class campaigns.[hhs2024changehealthcare]— U.S. Department of Health and Human Services public advisory on the Change Healthcare incident and HPH-sector response, 2024.[chainalysis2024alphvexit]— Chainalysis forensic write-up of the ALPHV / BlackCat exit-scam and Change Healthcare ~$22M Bitcoin ransom-payment tracing, 2024.[trm2024changehealthcare]— TRM Labs forensic write-up of the Change Healthcare ransom payment, on-chain tracing and operator-vs-affiliate divergence, 2024.[chainalysis2025ransomware]— Chainalysis 2024-recap ransomware report (referenced from G05 as well); documents the post-exit-scam ALPHV volume collapse and the RansomHub-successor affiliate-dispersal pattern.[reuters2023meridianlinksec]— Reuters reporting on the November 15, 2023 ALPHV SEC-filing pressure tactic against MeridianLink.[bleepingcomputer2023meridianlinksec]— BleepingComputer reporting on the MeridianLink SEC-filing tactic, including the leak-site screenshot of the SEC tip-submission portal.[wired2024changehealthcareransom]— Wired reporting on the Change Healthcare ~$22M Bitcoin ransom payment, February 2024.[ofac2022tornado]— sector-wide mixer-laundering enforcement context (referenced for the post-2022 ransomware-mixer-share decline, not for shared cluster identity).
Discussion
On the attribution-strength split. The ALPHV / BlackCat operator-cluster attribution is confirmed at the disruption-and-indictment layer — coordinated FBI / CISA / HHS public actions in December 2023, multiple Scattered Spider DOJ indictments across 2024, sustained multi-vendor industry-forensic corroboration — but is not OFAC-SDN-confirmed at the cluster level. ALPHV and its named affiliates were not OFAC-designated within the cluster's operating window. This is operationally important: the Change Healthcare ransom payment in February 2024 was traced in close to real time but was not freezable under v0.1 enforcement architecture, because no ALPHV-cluster wallet held an SDN listing. Compared to OAK-G05 LockBit (where Operation Cronos produced same-day SDN designations of two named affiliates and ten cryptocurrency-address SDN identifiers), G10 is the adjacent counter-factual: a closely-comparable Russian-language RaaS cluster that ran for 2.5 years, paid out an order of $100M-or-more in extortion proceeds, and exited via operator-side scam rather than law-enforcement seizure precisely because the OFAC-SDN architecture never caught up with it. OAK contributors writing G10-attributed examples should preserve this attribution-strength split per-incident, and should not infer OFAC-style asset-freeze-readiness from the underlying confirmed-grade cluster attribution.
On why OAK-G10 is RaaS-operation rather than individual-affiliate and not encryptor-strain. Naming this Group entry "ALPHV encryptor" or "BlackCat ransomware family" would have been the conventional external-framework framing (ALPHV is tracked under external Software ID S1068 and external Group ID G1008), but would mis-frame the operational continuity model in the same way that the analogous framing would mis-frame OAK-G05. The Rust-based ALPHV encryptor codebase rotated across versions, partial source code was leaked or recovered through industry tooling, and the post-exit-scam affiliate dispersal carried operational continuity into successor-brand RaaS strains rather than into ALPHV-codebase forks; the operator-and-affiliate-cluster is a cleaner persistent identity than the strain. By the same logic, naming the Group at the individual-affiliate level (Notchy, the Scattered Spider members named in DOJ indictments) would mis-frame the service-layer-persistence pattern that defines RaaS operationally. OAK-G10 sits at the same level of abstraction as OAK-G05 (LockBit RaaS) and OAK-G02 (Drainer-as-a-Service), with the difference that G10's per-named-operator attribution is confirmed-by-disruption-and-indictment-grade rather than confirmed-by-OFAC-SDN-designation-grade.
On the relationship to OAK-G05 (cluster boundary). G05 (LockBit) and G10 (ALPHV / BlackCat) share Russian-language operator substrate, operate the same RaaS business model, and overlap in affiliate cohorts (multiple criminal-forum operators ran intrusions against both LockBit and ALPHV depending on negotiated cuts and operational availability). They differ along four cluster-boundary axes: (1) Tooling: LockBit's encryptor lineage is C++-and-assembly-rooted (with a 2024 LockBit-NG-Dev pre-release the first significant tooling-architecture pivot); ALPHV was the first major Rust-based RaaS strain, with cross-platform Windows/Linux/ESXi builds from a shared codebase. (2) Affiliate-management style: LockBit ran a more centralised affiliate panel under a single principal operator (LockBitSupp / Khoroshev) with documented disciplinary actions against affiliates who violated cluster norms; ALPHV ran a more affiliate-favourable economic split (~80–90% to affiliates versus LockBit's ~80%) and a more heterogeneous affiliate cohort spanning Russian-speaking and English-speaking operators including the Scattered Spider crew. (3) Exit dynamics: LockBit was disrupted by coordinated multinational law enforcement (Operation Cronos, February 2024) with same-day OFAC designations of named affiliates; ALPHV exited via operator-side scam (March 2024) with no OFAC designation at the cluster level. (4) Public-attribution surface: LockBit produced a confirmed-by-OFAC-SDN-designation cluster (with named-defendant indictments and ten SDN-listed cryptocurrency addresses); ALPHV produced a confirmed-by-disruption-and-indictment cluster without OFAC-SDN-listed cryptocurrency addresses. The two clusters should not be conflated: a defender's anti-G05 watchlist surface (the ten OFAC-SDN-listed addresses, the Garantex-concentrated downstream rail) is structurally different from a defender's anti-G10 watchlist surface (industry-forensic-only, no SDN anchor, more diversified downstream rail).
On the relationship to OAK-G03. G03 (Russian laundering infrastructure, Garantex / Grinex / A7A5 lineage) was a documented downstream venue for some fraction of ALPHV proceeds, but the G10 / G03 chain is less concentrated than the G05 / G03 chain. ALPHV's affiliate cohort was more heterogeneous and the operator-side off-ramp profile in the Change Healthcare exit-scam shows broader laundering-rail distribution than the LockBit profile shows. Defenders running OAK-G03 watchlists should expect some overlap with G10-attributed inflows but should not expect the dense overlap they would expect with G05-attributed inflows.
On the SEC-filing tactic as operator-behaviour evolution rather than on-chain Technique. The November 2023 MeridianLink SEC-filing case is a tactical-novelty marker that defender control-set design needs to internalise even though it is not an OAK-T-classifiable on-chain Technique. The operator-pressure-tactic surface in ransomware extortion has expanded across 2023–2025 from leak-site naming-and-shaming to victim-customer / victim-employee outreach, regulator-disclosure-regime weaponisation (the SEC-filing tactic and its successors at RansomHub and Cl0p), and selective press-disclosure leverage. OAK should not absorb operator-pressure-tactic novelty into its on-chain Tactic catalog at v0.1 — it would dilute the on-chain framing — but G10's documentation should preserve the marker for downstream consumers building incident-response runbooks. The defender takeaway is that ransomware negotiation in 2024-and-after operates under a substantively different disclosure-regime threat model than it did in 2022, and counter-party-screening control sets need to assume that operator pressure on the regulator-disclosure surface is part of the negotiation environment.
On the exit-scam dynamic and the asset-freeze counter-factual. The Change Healthcare case is the canonical worked example, on the public record, of the real-time-traced ransomware payment that was not frozen. Industry forensic providers traced the ~$22M Bitcoin payment within hours of confirmation; the operator-side exit-scam off-ramped a substantial fraction of those proceeds within days; no OFAC-SDN-listed-wallet enforcement action was available, because no ALPHV-cluster wallet held an SDN listing at the time. This is the load-bearing counter-factual for the broader argument that on-chain visibility is necessary but not sufficient for ransomware-payment recovery — enforcement reach (administrative SDN designations on receiving wallets, regulated-CEX cooperation downstream, Tornado-Cash-class designations on intermediating infrastructure) is the binding constraint. Compared to G05 LockBit, where same-day OFAC SDN designations of ten cryptocurrency addresses produced a partial freeze surface against affiliate-controlled flows, G10 produced no freeze surface despite confirmed-grade attribution at every layer except the OFAC-SDN-designation layer. The lesson for v0.x OAK content and for downstream defenders / regulators / exchanges is that attribution without designation does not produce a freeze, and that the public-policy interval between cluster-attribution and SDN-designation is itself a material exposure window during which traced proceeds can off-ramp under the operator's full control.
On the affiliate-vs-operator divergence. The Change Healthcare exit-scam is also the canonical case where the affiliate-vs-operator partition of RaaS proceeds becomes operationally visible on-chain. Notchy (the affiliate) ran the intrusion and was contractually due the affiliate-cut share of the $22M payment; the ALPHV operator absconded with that share and posted a fabricated FBI-seizure banner. Industry forensic reconstruction shows the operator-side flow taking a different downstream path than the affiliate-side residual flow. This partition matters for defender attribution because it shows that cluster-level wallet attribution is not the same as principal-level wallet attribution within a cluster; the OAK-T8.001 (Common-Funder Cluster Reuse) attribution-side Technique can identify the cluster but does not partition operator-from-affiliate within it without additional signal (forum-disclosure of the dispute, operator-persona reuse on successor brands, downstream-venue concentration). G10's documentation preserves this distinction explicitly, and OAK contributors writing G10-attributed examples should mark whether each on-chain flow is operator-side, affiliate-side, or unresolved.
On v0.x evolution. G10's 2026+ trajectory will depend on (a) whether further DOJ Scattered Spider indictments and successor-brand (RansomHub, Cl0p, Akira) attributions extend the cluster-continuity attestation, (b) whether OFAC retroactively designates ALPHV-cluster wallets — possible but not highly probable, given the cluster's terminal-phase status and the tendency of OFAC enforcement to concentrate on still-active operators — (c) whether a worked example of the Change Healthcare incident is added under examples/ once the per-flow attribution surface stabilises sufficiently, and (d) whether the operator-pressure-tactic novelty surface produces sufficient successor-brand instances to warrant a dedicated v0.x OAK Tactic for regulator-disclosure-regime weaponisation outside the on-chain framing. OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates. Future OAK Group additions in the ransomware sector — Conti-successor brands, RansomHub as a standalone successor-brand entry, Cl0p, Scattered Spider as a multi-RaaS-affiliate cluster in its own right — would each warrant their own OAK-Gnn entry rather than extension of G05 or G10, on the same per-cluster identity principle.