Threat actor · OAK-G11
OAK-G11 — Black Basta Ransomware-as-a-Service operation
Description
OAK-G11 is the Black Basta ransomware-as-a-service operation: a Russian-language operator network that, between April 2022 and the late-2024-to-Q1-2025 internal wind-down, was one of the highest-volume RaaS strains in the post-Conti window alongside OAK-G05 LockBit, OAK-G10 ALPHV / BlackCat, and OAK-G14 Cl0p. The cluster is genuinely distinct from prior OAK Groups along multiple axes: from OAK-G05 LockBit and OAK-G10 ALPHV along the Conti-organisational-lineage axis (Black Basta is a documented Conti-splinter cluster, structurally shaped by the February-to-May 2022 ContiLeaks dispersal; LockBit and ALPHV are independently-founded operating brands that pre-date the Conti dispersal), along the operator-cut-economics axis (Black Basta affiliate splits are reported in the ~70 / 30 affiliate / operator range, midway between LockBit's ~80 / 20 and ALPHV's ~85 / 15), and along the attribution-surface axis (Black Basta is confirmed-at-cluster-level-by-CISA-advisory but lacks the OFAC-SDN designations of G05 and the DOJ-indictment density of G10's Scattered Spider affiliate stream). Black Basta's inclusion in OAK is not because it is a crypto-native operator — its targets are overwhelmingly traditional-enterprise IT estates, with U.S. healthcare sector firms heavily over-represented in the public victim record — but because cryptocurrency is the load-bearing payment-and-laundering rail of the entire RaaS business model, because the cluster's Conti-organisational-continuity is the canonical worked example in the public record of post-leak-driven-rebrand operator-cohort persistence, and because the May 2024 Ascension Health attack is the largest publicly-attributed Black Basta intrusion against a U.S. healthcare-sector primary target and stands as a high-salience defender case alongside the Change Healthcare incident under OAK-G10.
The operational model is a textbook Conti-lineage ransomware-as-a-service split with several cluster-distinctive features. Black Basta's encryptor lineage carries forward Conti-codebase architectural choices into a redeveloped Rust-and-C++ implementation with cross-platform Windows / Linux / VMware ESXi builds; the cluster was an early adopter of double-extortion-with-data-theft as the default negotiation posture, with the leak-site naming-and-shaming surface used aggressively from the cluster's first quarter of operation. The QakBot loader chain was the canonical Black Basta initial-access vector during 2022–2023, with Cobalt Strike post-exploit tooling and Empire / BloodHound lateral-movement; following the August 2023 FBI / DOJ Operation Duck Hunt disruption of QakBot infrastructure, Black Basta affiliates shifted to DarkGate, Pikabot, and Cobalt-Strike-via-third-party-loader chains as primary delivery mechanisms. The cluster intersected substantially with the broader Russian-language affiliate cohort — multiple operators on RAMP and other forums ran intrusions against both Black Basta and Conti-successor brands, with affiliate-cluster boundaries enforced primarily by economic incentive rather than by exclusivity contracts. Per the Elliptic 2024 retrospective ([elliptic2024blackbasta]), approximately $107M in confirmed Bitcoin ransom payments traced to Black Basta-attributable wallet clusters across the first 18 months of operation; the cluster's overall extortion-revenue trajectory through late-2024 puts it in the top-five RaaS strains by volume across the 2022-2024 window per multi-vendor industry-forensic aggregates, alongside OAK-G05 LockBit, OAK-G10 ALPHV, OAK-G14 Cl0p, and the post-2024 RansomHub-as-ALPHV-successor cohort.
The cluster's defender-relevant signature is upstream-extraction-cluster with Conti-lineage organisational continuity, confirmed-grade attribution at the CISA-advisory layer (rather than the OFAC-SDN layer), and a 2.5-year operating window terminated by internal wind-down following internal-chats leak rather than by law-enforcement seizure or operator-side scam. The May 2024 Ascension Health attack — which encrypted the IT estate of one of the U.S.'s largest non-profit Catholic-affiliated hospital networks (140+ hospitals, 40+ senior-living facilities, ~140,000 staff), produced multi-week clinical-IT-system outages across the network, and was specifically cited in the AA24-131A advisory as the basis for the joint-advisory escalation tempo — is the cluster's highest-salience public-record case and the canonical worked example of a Black-Basta-attributed healthcare-sector intrusion. The cluster also overlapped with the broader 2023 MOVEit campaign attack-surface — multiple Black Basta affiliate intrusions in mid-2023 leveraged MOVEit-class managed-file-transfer compromises as initial-access stepping stones, in parallel to (but not attributable to) the OAK-G14 Cl0p mass-extortion campaign. Defenders running G11-tuned controls should expect substantial overlap with G05 / G10 / G14 control-set design at the off-chain intrusion layer; the on-chain layering surface is more diversified than the G05 LockBit profile but follows the broader Russian-language commercial-criminal off-ramp pattern.
Targeting profile
OAK-G11's victim profile is enterprise-IT rather than crypto-native, with sector concentration in U.S. healthcare, manufacturing, financial services, and government / public sector:
- U.S. healthcare-sector firms — Ascension (May 2024, the canonical high-salience case; multi-week clinical-IT outage across 140+ hospitals), Capital Health (November 2023), Hillside Children's Center, multiple regional hospital systems and clinical networks; healthcare over-representation in the Black Basta record was a stated reason for the AA24-131A joint-advisory issuance and for HHS-sectoral-response tempo.
- Manufacturing and industrial-sector firms — ABB (May 2023, with reported business-interruption impact across the firm's global manufacturing operations), Yellow Corporation (2023), Knauf Group, Hyundai Motor Europe (January 2024); manufacturing over-representation in the Black Basta record reflects the broader RaaS-sector targeting profile.
- Financial-sector firms — Capita (March 2023, U.K. outsourcing firm with substantial financial-sector and public-sector contract exposure), various regional banks and credit unions; financial-sector targeting was less concentrated than in the G05 LockBit profile.
- Government and public-sector organisations — multiple U.S. state and municipal governments, education-sector targets, and non-U.S. government bodies; targeting profile broadly consistent with cross-sector Conti-successor-cohort behaviour.
- Cryptocurrency-industry firms as occasional targets — present but not the dominant target class; G11 is enterprise-extortion-led, not crypto-native-extraction-led, and no Black Basta intrusion against a crypto-firm primary target reaches the public-record salience of any G01 / G08 incident.
- Downstream cryptocurrency users — only as secondary victims of the laundering rails the operation depends on (the load on the Russian-language commercial-criminal off-ramp surface from G11 flows is part of the volume that produced the OAK-G03 sanctions cycle, though G11 was less Garantex-concentrated than the G05 LockBit profile per industry-forensic reconstruction).
Observed Techniques
OAK v0.1's Tactic catalog is on-chain-extraction-focused; Black Basta's intrusion surface (off-chain enterprise IT compromise via QakBot / DarkGate / Pikabot loader chains, Cobalt-Strike post-exploit, ESXi-host-targeted encryption) sits outside that scope and is documented under external Group ID G1037 in the conventional cyber-threat-intel taxonomy. The on-chain Techniques observed in OAK-G11-attributable activity are concentrated on the payment-and-laundering side:
- OAK-T7.001 (Mixer-Routed Hop) — observed as a partial / earlier-stage component of the broader Black Basta laundering chain, with usage declining sharply across 2023–2024 in step with the sector-wide decline driven by the OFAC Tornado Cash designation (
[ofac2022tornado]) and the Sinbad takedown; per[chainalysis2025ransomware]mixer-share of ransomware-laundering volume fell substantially across 2023–2024 as a sector-wide effect and Black Basta followed the trend. - OAK-T7.002 (CEX Deposit-Address Layering) — the canonical post-2023 Black Basta affiliate off-ramp for the Bitcoin portion of ransom payments, with affiliate-controlled deposit-address activity at non-KYC and lax-KYC venues a recurring industry-forensic signature; the Elliptic 2024 retrospective documents the deposit-address-layering pattern across the cluster's wallet set.
- OAK-T7.003 (Cross-Asset / Cross-Chain Laundering) — observed as a cluster-distinctive component of the Black Basta laundering chain, with Bitcoin-to-Monero conversion as a downstream privacy-coin layering step and Bitcoin-to-stablecoin conversion through non-KYC and lax-KYC venues as a fiat-on-ramp preparation step.
- OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by Mandiant, Chainalysis, TRM Labs, and Elliptic to maintain Black Basta affiliate-cluster identification across encryptor-version rotations, across the Conti-shutdown / Black-Basta-launch organisational-continuity window, and across the post-2024 affiliate-dispersal-into-RansomHub / Akira / Cactus continuity. The persistence of Bitcoin-funder-cluster identity across the Conti dispersal is the single highest-signal indicator of operator continuity in the ransomware sector for the 2022-cohort.
- OAK-T8.002 (Cross-Chain Operator Continuity) — observed in the affiliate-dispersal pattern after Q1 2025, with multiple Black Basta affiliates re-surfacing on RAMP and other Russian-language criminal forums under reused persona identifiers and known-cluster wallet-funder signatures across successor RaaS engagements.
- Adjacent / pre-incident vectors not in OAK v0.1 scope: off-chain initial access via the QakBot loader chain (pre-August 2023) and DarkGate / Pikabot / Cobalt-Strike-via-third-party-loader chains (post-August 2023), exposed-RDP and VPN exploitation, exploitation of public-facing vulnerabilities (Microsoft Exchange ProxyShell-class, Confluence, Citrix Bleed, Veeam Backup, MOVEit-class managed-file-transfer products), and Active-Directory-trust-relationship abuse for ESXi-host targeting; these are the canonical Black Basta affiliate intrusion vectors and overlap substantially with the broader Conti-successor-cohort intrusion-vector profile.
Observed Examples
No public incidents at v0.1 — worked examples pending per-incident forensic publication.
OAK v0.1 does not yet contain a worked example whose primary axis is a Black Basta target; the on-chain angle of G11 is the laundering of ransom payments rather than direct crypto-firm intrusion, and the cluster's most defender-relevant payment-tracing case (Ascension) is on the watch-list for v0.x worked-example coverage. The high-salience public-record events anchoring the cluster:
- CISA / FBI / HHS / MS-ISAC AA24-131A joint advisory (May 10, 2024). "StopRansomware: Black Basta" — characterising the cluster's TTPs across the healthcare and other critical-infrastructure sectors, naming Black Basta as a closed RaaS operating brand with hundreds of named victims across 12 of 16 critical-infrastructure sectors, and identifying the cluster's QakBot-to-DarkGate / Pikabot loader-chain pivot following the August 2023 Operation Duck Hunt QakBot disruption (
[cisa2024aa24131ablackbasta]). Attribution at confirmed at the cluster level. - Ascension ransomware incident (May 8, 2024). Black Basta-attributed encryption of the Ascension IT estate, producing multi-week clinical-IT-system outages across 140+ hospitals (electronic health records, medication-management systems, patient-portal access); specifically cited in the May 10 AA24-131A advisory as a precipitating factor for the joint-advisory escalation tempo (
[ascension2024incident],[hhs2024ascension]). The largest publicly-attributed Black Basta intrusion against a U.S. healthcare-sector primary target on the public record. Attribution at confirmed at the cluster level. - MOVEit-campaign overlap activity (mid-2023). Multiple Black Basta affiliate intrusions in mid-2023 leveraged MOVEit-class managed-file-transfer compromises as initial-access stepping stones, in parallel to (but not attributable to) the OAK-G14 Cl0p mass-extortion campaign of June 2023. Documented at inferred-strong per Mandiant UNC4393 and Microsoft Storm-1811 / Storm-0506 sub-cluster attribution. The Black-Basta-vs-Cl0p MOVEit-campaign cluster boundary is operationally meaningful: Cl0p ran exclusive-vendor mass-exploitation against the MOVEit zero-day (CVE-2023-34362); Black Basta-aligned affiliates ran opportunistic exploitation of MOVEit-derived victim disclosures and credential exposures in the post-Cl0p tail period.
- BlackBastaLeaks internal-chats archive (February 2025). Anonymous insider leak of approximately 200,000 Jabber / Matrix messages from within the Black Basta operator-and-affiliate cohort, surfacing operational-organisational structure, encryptor-development decisions, affiliate-disciplinary actions, and victim-negotiation tactics; structurally parallel to the February-to-May 2022 ContiLeaks event for the Conti cluster (
[blackbastaleaks2025]). Attribution at confirmed at the cluster level (the leaked chats are on the public record); the leak's downstream effect on cluster wind-down dynamics is inferred-strong per industry-forensic tracking. - Aggregate Black Basta metrics from
[cisa2024aa24131ablackbasta](>500 victim organisations across the cluster's first 24 months per the May 2024 advisory; cross-sector targeting across 12 of 16 critical-infrastructure sectors) and from[elliptic2024blackbasta](~$107M in confirmed Bitcoin ransom payments traced to Black Basta-attributable wallet clusters across the first 18 months of operation; cluster-share of total ransomware payments declining through Q4 2024 in step with the broader cluster wind-down). - Worked examples for specific G11-mediated ransom-payment laundering flows are pending v0.x and will live under
examples/once the per-incident attribution surface stabilises sufficiently for the OAK confirmed / inferred-strong distinction; the Ascension case is the highest-priority candidate.
Citations
[cisa2024aa24131ablackbasta]— CISA / FBI / HHS / MS-ISAC joint cyber-security advisory AA24-131A, "StopRansomware: Black Basta," May 10, 2024.[elliptic2024blackbasta]— Elliptic 2024 retrospective on Black Basta ransom-payment tracing; ~$107M in confirmed Bitcoin payments across the first 18 months of operation.[mandiantunc4393]— Mandiant UNC4393 tracker write-up on Black Basta operator-cohort attribution and the QakBot-to-DarkGate / Pikabot loader-chain pivot.[microsoftstorm1811]— Microsoft Threat Intelligence blog on Storm-1811 / Storm-0506 sub-cluster activity within the Black Basta affiliate cohort.[blackbastaleaks2025]— Anonymous insider release of approximately 200,000 internal Black Basta Jabber / Matrix chats, February 2025.[ascension2024incident]— Ascension public statements and incident-response disclosures regarding the May 2024 ransomware incident.[hhs2024ascension]— U.S. Department of Health and Human Services public-sector advisory on the Ascension incident and HPH-sector response, 2024.[contileaks2022]— ContiLeaks insider leak (February-to-May 2022); foundational organisational-continuity context for the Conti-to-Black-Basta dispersal pattern.[chainalysis2025ransomware]— Chainalysis 2024-recap ransomware report (referenced from G05 and G10 as well); documents Black Basta cluster-share trajectory and post-Q1-2025 affiliate-dispersal dynamics.[ofac2022tornado]— sector-wide mixer-laundering enforcement context (referenced for the post-2022 ransomware-mixer-share decline, not for shared cluster identity).
Discussion
On the attribution-strength split. The Black Basta operator-cluster attribution is confirmed at the CISA-advisory layer — the May 2024 AA24-131A joint advisory by CISA, FBI, HHS, and MS-ISAC is the canonical national-government-coordinated public attribution document for the cluster — but is not OFAC-SDN-confirmed or DOJ-indictment-confirmed at the principal-operator level as of v0.1. This makes G11 a confirmed-by-CISA-advisory rather than confirmed-by-OFAC-SDN-designation case, structurally adjacent to OAK-G10 ALPHV / BlackCat (which is confirmed-by-disruption-and-indictment) and structurally distinct from OAK-G05 LockBit (which is confirmed-by-OFAC-SDN-designation-and-DOJ-indictment). OAK contributors writing G11-attributed examples should preserve this attribution-strength split per-incident, and should not infer OFAC-style asset-freeze-readiness from the underlying confirmed-grade cluster attribution. Attribution that specific affiliate operators are tied to specific real-world identities is inferred-strong per the BlackBastaLeaks internal-chats archive and per Mandiant / Microsoft sub-cluster tracking; no DOJ unsealings of Black-Basta-principal-operator indictments have been issued as of v0.1.
On the Conti-to-Black-Basta organisational continuity. Black Basta's launch in April 2022 came out of the February-to-May 2022 ContiLeaks dispersal window — Conti's internal Jabber chats, source code, and operator documents were leaked publicly by an anonymous insider in February 2022, the cluster's external-facing operations wound down across March-to-May 2022, and a series of successor RaaS brands launched in the same period (Black Basta, Royal, Akira, Quantum, BlackByte, Karakurt). The Conti-to-Black-Basta organisational-continuity claim is inferred-strong — overlap of operator personas across the dispersal window, Bitcoin-funder-cluster reuse from Conti-attributable wallets to early-Black-Basta wallets, shared TTPs (QakBot loader chain, Cobalt Strike post-exploit, Empire / BloodHound lateral-movement), shared encryptor-architecture decisions, and the February 2025 BlackBastaLeaks internal-chats archive's surfacing of operator-cohort references to Conti-era organisational structure. OAK-G11's documentation preserves this organisational-continuity attestation at inferred-strong and should be read alongside any future OAK-Gnn entry that addresses other Conti-successor brands (Royal / Akira / Quantum / BlackByte / Karakurt) on the same per-cluster identity principle.
On the cluster-boundary distinction with OAK-G05 LockBit and OAK-G10 ALPHV. G05, G10, and G11 share Russian-language operator substrate, operate the same RaaS business model, and overlap substantially in affiliate cohorts (multiple criminal-forum operators ran intrusions against multiple RaaS brands depending on negotiated cuts and operational availability). The three clusters differ along the organisational-lineage axis (G11 is Conti-splinter; G05 and G10 are independently-founded), the attribution-surface axis (G05 = OFAC-SDN + DOJ indictments; G10 = FBI disruption + DOJ Scattered Spider indictments; G11 = CISA advisory + leaked-internal-chats), and the exit-dynamic axis (G05 = law-enforcement seizure via Operation Cronos; G10 = operator-side exit-scam; G11 = internal wind-down following internal-chats leak). Defenders running anti-G05 / anti-G10 / anti-G11 watchlist surfaces should expect substantial off-chain-intrusion-vector overlap (loader chains, post-exploit tooling, lateral-movement) but should expect distinct on-chain attribution surfaces — G05's ten OFAC-SDN-listed cryptocurrency addresses are not shared with G10 or G11; G10's industry-forensic-only attribution surface is structurally similar to G11's; G11's Bitcoin-funder-cluster persistence across the Conti-to-Black-Basta window is the cluster's distinctive forensic signature.
On the relationship to OAK-G03. G03 (Russian laundering infrastructure, Garantex / Grinex / A7A5 lineage) was a documented downstream venue for some fraction of Black Basta proceeds, but the G11 / G03 chain is less concentrated than the G05 / G03 chain. Black Basta's affiliate cohort was more heterogeneous in downstream-venue selection and the cluster's broader Russian-language commercial-criminal off-ramp profile shows distribution across multiple non-KYC and lax-KYC venues rather than dense concentration at any single downstream rail. Defenders running OAK-G03 watchlists should expect some overlap with G11-attributed inflows but should not expect the dense overlap they would expect with G05-attributed inflows.
On v0.x evolution. G11's 2026+ trajectory will depend on (a) whether further DOJ unsealings or OFAC designations of Black-Basta-principal-operators emerge, possibly downstream of the BlackBastaLeaks internal-chats archive's evidentiary surface; (b) whether successor-brand affiliate-continuity attestation extends across RansomHub / Akira / Cactus / other 2025-active brands; (c) whether a worked example of the Ascension incident is added under examples/ once the per-flow attribution surface stabilises sufficiently; and (d) whether additional Conti-successor brands (Royal, Akira, Quantum, BlackByte, Karakurt) are added as separate OAK-Gnn entries. OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates. Future OAK Group additions in the ransomware sector — additional Conti-successor brands, Scattered Spider as a multi-RaaS-affiliate cluster in its own right (now OAK-G12), Cl0p (now OAK-G14), RansomHub as a standalone successor-brand entry — would each warrant their own OAK-Gnn entry rather than extension of G05 / G10 / G11, on the same per-cluster identity principle.