Threat actor · OAK-G13
OAK-G13 — Iranian financially-motivated cyber operators (MuddyWater + Charming Kitten + Pioneer Kitten cluster set)
Description
OAK-G13 is the Iranian financially-motivated cyber-operators cluster set: a state-aligned cohort of IRGC-and-MOIS-affiliated cyber-actor sub-clusters whose mission portfolio is espionage-primary, financial-and-disruptive-secondary, distinct from the OAK-G01 Lazarus Group cluster (DPRK / RGB primary mission is regime-revenue-generating crypto theft) and from the OAK-G07 APT43 / Kimsuky cluster (DPRK / RGB primary mission is strategic cyber-espionage with cryptocurrency theft as a self-funding support function). The cluster set is genuinely distinct from prior OAK Groups along multiple axes: from G01 along the Iran-vs-DPRK state-substrate axis and the cryptocurrency-as-mission-axis-vs-cryptocurrency-as-secondary-monetisation-axis (Iranian operators do not produce DPRK-scale aggregate cryptocurrency-theft volumes, and the cryptocurrency angle is a secondary monetisation surface across multiple sub-cluster missions rather than a primary-mission organising principle); from G07 along the Iran-vs-DPRK axis and the Iranian-state-mission-portfolio axis (Iranian sub-clusters' cryptocurrency exposure includes ransomware-with-crypto-payments, cryptocurrency-mining intrusions, and sanctions-evasion-adjacent activity in addition to direct theft, while G07's exposure is dominated by self-funding-driven theft); and from the Russian-language commercial-criminal cluster set (G05, G10, G11, G14) along the state-aligned-vs-commercial-criminal axis. OAK-G13's inclusion in the v0.1 actor catalog is not because Iranian operators produce DPRK-scale or commercial-RaaS-scale aggregate cryptocurrency volumes — they do not — but because the cluster set has produced foundational sanctions-precedent activity (the November 2018 OFAC SamSam-laundering designation introduced cryptocurrency-address SDN identifiers to the U.S. sanctions architecture), novel ransomware-with-crypto-payment operational patterns (the Pay2Key operation of late-2020 was an Iranian-state-aligned ransomware campaign with Bitcoin-denominated ransom payments and Israeli-target concentration, structurally distinct from commercial RaaS), and sustained sanctions-and-enforcement tempo through 2024 that warrants stable Group identification in OAK.
The operational model varies across the three sub-clusters in the set. MuddyWater (MOIS-attributed) operates a sustained-espionage-and-disruption mission against telecommunications, government, defense, and oil-and-gas-sector targets across the Middle East, Europe, North America, and Asia, with TTPs centred on PowerShell-based loader chains, custom backdoors (POWERSTATS, MORI, Small Sieve), and exploitation of public-facing-application vulnerabilities; cryptocurrency-economy exposure is concentrated on cryptocurrency-mining intrusions on compromised infrastructure — using compromised victim resources for unauthorized cryptocurrency-mining as a residual-monetisation surface — and on occasional ransomware-with-crypto-payment activity. Charming Kitten / APT35 (IRGC-IO-attributed) operates a sustained-espionage mission against academic, journalist, dissident, U.S.-and-Israeli-government, and human-rights-organisation targets, with TTPs centred on credential-harvesting via fabricated-persona social engineering (academic-conference-invitation lure, journalist-interview-request lure), spear-phishing, and (per CISA AA22-055A and adjacent advisories) Log4Shell exploitation; cryptocurrency-economy exposure is concentrated on credential-harvesting and account-takeover-led cryptocurrency-account compromise against individual targets, with the cluster's core mission remaining espionage-led. Pioneer Kitten / Fox Kitten / Lemon Sandstorm / UNC757 (IRGC-affiliated) operates a hybrid-state-aligned-and-financially-motivated mission, with FBI / CISA AA20-259A documenting the cluster's exploitation of VPN-vulnerability-enabled access for both state-directed espionage objectives and for sale to ransomware affiliates as initial-access-broker activity, and the August 2024 FBI Flash documenting continued cluster activity through 2024; the initial-access-broker-to-ransomware-affiliate sale operational pattern is the most-cryptocurrency-economy-exposed of the three sub-clusters and is the closest Iranian-cluster analogue to the broader Russian-language affiliate-broker market.
The cluster's defender-relevant signature is state-aligned-and-financially-motivated, with sanctions-precedent-grade public-attribution surface, a less-prolific cryptocurrency-economy footprint than DPRK or Russian-language clusters, but distinctive in its sanctions-evasion-and-Iranian-economy-overlap exposure. The Pay2Key ransomware operation of November-to-December 2020 is the canonical worked case in the public record: per Check Point and ClearSky tracking, Pay2Key ran approximately 80 named-victim intrusions against predominantly Israeli targets across a six-week window, with Bitcoin-denominated ransom payments demanded and the operation's wallet infrastructure showing on-chain links to OFAC-designated Iranian-cryptocurrency-exchange counterparties ([checkpoint2020pay2key], [clearsky2020pay2key]); the operation's combination of Israeli-target concentration, short campaign window, and on-chain link to Iranian-economy off-ramp infrastructure is structurally distinct from commercial-RaaS profile and was widely interpreted as a state-directed-with-cryptocurrency-payment-cover operation. The November 2018 OFAC SamSam-laundering designation ([ofac2018samsam]) — designating Khorashadizadeh and Ghorbaniyan and including their cryptocurrency addresses on the SDN List as identifiers for the first time — is the foundational sanctions-precedent event for cryptocurrency-address-on-SDN-List enforcement architecture and is cited from OAK-G05 / G10 / G11 documentation as the precedent that subsequently produced the LockBit-affiliate-address SDN designations and adjacent enforcement actions. The cluster set's broader cryptocurrency-mining-intrusion-on-compromised-infrastructure activity — using cryptojacking on victim systems as a residual-monetisation surface — is a documented IRGC-and-MOIS-aligned operational pattern that overlaps with adjacent OAK-G09 Andariel cryptojacking activity and warrants joint-defender-control consideration.
Targeting profile
OAK-G13's victim profile spans the cluster set's distinct primary missions and produces cryptocurrency-economy exposure through several distinct channels:
- Telecommunications, oil-and-gas, government, and defense-sector targets across the Middle East, Europe, North America, and Asia — MuddyWater's canonical primary-mission target class per CISA AA22-055A and multi-vendor industry-forensic tracking; cryptocurrency-economy exposure here is via cryptocurrency-mining-intrusion residual-monetisation rather than direct theft.
- Academic, journalist, dissident, U.S.-and-Israeli-government, and human-rights-organisation targets — Charming Kitten / APT35's canonical primary-mission target class; cryptocurrency-economy exposure here is via credential-harvesting-led individual-cryptocurrency-account compromise and (in some documented cases) extortion of Iranian dissidents and Iranian-diaspora individuals with cryptocurrency-account exposure.
- VPN-vulnerability-exposed enterprise targets across multiple sectors — Pioneer Kitten / Fox Kitten / Lemon Sandstorm's canonical primary-mission target class per CISA AA20-259A; cryptocurrency-economy exposure here is via initial-access-broker sale of compromised access to ransomware affiliates, with ransom-payment cryptocurrency flow downstream.
- Israeli targets across multiple sectors — Pay2Key (late-2020) and adjacent Iranian-state-aligned operations against Israeli targets show concentrated targeting that overlaps with the cluster set's broader IRGC-vs-Israel adversarial posture; the November-to-December 2020 Pay2Key campaign is the highest-public-record-salience case.
- U.S.-and-allied government, contractor, and election-security targets — IRGC-aligned activity through 2024 against U.S. government and election-security infrastructure (the August 2024 FBI Flash documented Pioneer Kitten activity affecting U.S. presidential-campaign-related infrastructure), with cryptocurrency exposure peripheral to the espionage mission.
- Cryptocurrency-industry firms as occasional but not dominant targets — present in industry-forensic tracking but not the dominant target class for any of the three sub-clusters; G13 is state-aligned-espionage-led, not crypto-native-extraction-led.
- Victim infrastructure used for unauthorized cryptocurrency-mining — compromised victim systems across multiple sectors used for cryptojacking as a residual-monetisation surface, particularly attributed to MuddyWater and adjacent IRGC-affiliated activity.
Observed Techniques
OAK v0.1's Tactic catalog is on-chain-extraction-focused; G13's intrusion surface (off-chain spear-phishing under fabricated-persona social engineering, PowerShell loader chains, public-facing-application vulnerability exploitation, VPN-vulnerability exploitation, Log4Shell-class exploitation, credential-harvesting) sits outside that scope and is documented under the conventional cyber-threat-intel taxonomy Group IDs G0058 (Charming Kitten / APT35), G0069 (MuddyWater), and adjacent group profiles. The on-chain Techniques observed in OAK-G13-attributable activity are concentrated on the ransom-payment-laundering and sanctions-evasion-adjacent surface:
- OAK-T7.001 (Mixer-Routed Hop) — observed as a partial / earlier-stage component of the broader Iranian-cluster-set laundering chain, particularly for Pay2Key and adjacent ransomware-with-crypto-payment proceeds; usage of Bitcoin mixers for the BTC portion of Iranian-cluster proceeds declined sharply across 2022-to-2024 in step with the sector-wide post-Tornado-Cash-designation decline and the OFAC-2022-designation of multiple Iran-affiliated mixer-and-exchange counterparties.
- OAK-T7.002 (CEX Deposit-Address Layering) — observed in Iranian-cluster-set proceeds laundering, with Iranian-cryptocurrency-exchange-counterparty deposit-address activity (Khorashadizadeh / Ghorbaniyan-class infrastructure pre-2018 OFAC designation; subsequent Iran-affiliated exchange counterparties post-2018) a recurring industry-forensic signature; the November 2018 OFAC SamSam-laundering designation introduced cryptocurrency-address SDN identifiers to the U.S. sanctions architecture against this exact off-ramp pattern.
- OAK-T7.003 (Cross-Asset / Cross-Chain Laundering) — observed in Pay2Key-class proceeds laundering, with Bitcoin-to-stablecoin and Bitcoin-to-Iranian-economy off-ramp legs documented per Check Point and ClearSky tracking.
- OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by Mandiant, Microsoft, CrowdStrike, ClearSky, Check Point, and Chainalysis to maintain Iranian-cluster-set-attributable wallet-cluster identification across sub-cluster mission rotations and across the IRGC-vs-MOIS sub-cluster boundary; distinguishing MuddyWater wallet activity from Charming-Kitten or Pioneer-Kitten wallet activity is a non-trivial defender problem precisely because the three sub-clusters share IRGC-or-MOIS substrate and intermittently share infrastructure.
- Adjacent / pre-incident vectors not in OAK v0.1 scope: off-chain initial access via spear-phishing under fabricated-persona social engineering (Charming Kitten's canonical academic-conference-invitation and journalist-interview-request lures), PowerShell-based loader chains and custom backdoors (MuddyWater's POWERSTATS, MORI, Small Sieve toolset), VPN-vulnerability exploitation (Pioneer Kitten's canonical Pulse Secure, Citrix, Fortinet vector per CISA AA20-259A), Log4Shell-class public-facing-application vulnerability exploitation, and cryptojacking-on-compromised-infrastructure as a residual-monetisation surface (overlap with adjacent OAK-G09 Andariel cryptojacking activity).
Observed Examples
No public incidents at v0.1 — worked examples pending per-incident forensic publication.
OAK v0.1 does not yet contain a worked example whose primary axis is an Iranian-cluster-set target; the on-chain angle of G13 is distributed across ransomware-with-crypto-payments, cryptojacking, and sanctions-precedent SDN-listing events rather than concentrated on any single high-volume worked case. The high-salience public-record events anchoring the cluster set:
- November 2018 OFAC SamSam-laundering designation. OFAC designation of Iranian nationals Ali Khorashadizadeh and Mohammad Ghorbaniyan for laundering SamSam ransomware proceeds, including cryptocurrency addresses on the SDN List as identifiers for the first time (
[ofac2018samsam]). Foundational sanctions-precedent for cryptocurrency-address-on-SDN-List enforcement architecture; cited from OAK-G05 / G10 / G11 documentation as the precedent that subsequently produced the LockBit-affiliate-address SDN designations. Attribution at confirmed. - Pay2Key ransomware operation (November-to-December 2020). Iranian-state-aligned ransomware campaign against approximately 80 predominantly-Israeli-target victims across a six-week window, with Bitcoin-denominated ransom payments demanded and the operation's wallet infrastructure showing on-chain links to OFAC-designated Iranian-cryptocurrency-exchange counterparties (
[checkpoint2020pay2key],[clearsky2020pay2key]). Structurally distinct from commercial-RaaS profile (short campaign window, Israeli-target concentration, on-chain link to Iranian-economy off-ramp infrastructure). Attribution at inferred-strong per Check Point and ClearSky tracking; broader Iranian-state-substrate attribution at confirmed. - CISA AA22-055A "Iranian Government-Sponsored MuddyWater Actors" advisory (February 24, 2022). Joint CISA / FBI / NSA / U.K. NCSC / U.S. Cyber Command attribution of MuddyWater to Iran's Ministry of Intelligence and Security (MOIS), characterising the cluster's TTPs across telecommunications, government, defense, and oil-and-gas-sector targets (
[cisa2022aa22055a]). Attribution at confirmed. - CISA AA22-257A "Iranian IRGC-Affiliated Cyber Actors Exploiting Vulnerabilities for Data Extortion and Ransomware Operations" advisory (September 14, 2022). Joint CISA / FBI / NSA / U.S. Cyber Command / U.S. Treasury / U.K. NCSC / Australian Cyber Security Centre / Canadian Centre for Cyber Security advisory documenting IRGC-affiliated cyber-actor exploitation of vulnerabilities for ransomware and data-extortion operations against U.S. and allied targets (
[cisa2022aa22257a]). Attribution at confirmed. - CISA AA20-259A "Iran-Based Threat Actor Exploits VPN Vulnerabilities" advisory (September 15, 2020). Joint CISA / FBI advisory on Pioneer Kitten / Fox Kitten / Parisite VPN-vulnerability exploitation for both state-directed espionage and initial-access-broker sale to ransomware affiliates (
[cisa2020aa20259a]). Attribution at confirmed. - FBI Flash on Pioneer Kitten / Fox Kitten / Lemon Sandstorm activity (August 28, 2024). FBI public Flash documenting continued IRGC-affiliated Pioneer Kitten activity against U.S. and allied targets, including activity affecting U.S. presidential-campaign-related infrastructure (
[fbi2024pioneerkittenflash]). Attribution at confirmed. - Multiple OFAC designations against IRGC-affiliated cyber-units and individuals (2018-to-2024). Sustained OFAC designation tempo against IRGC-affiliated cyber actors and infrastructure, including the September 2020 designation of APT39-affiliated Rana Intelligence Computing Company and the September 2022 designation of multiple IRGC-affiliated individuals for ransomware-and-data-extortion operations (
[ofac2020apt39],[ofac2022irgcyber]). Attribution at confirmed. - MuddyWater cryptojacking-on-compromised-infrastructure activity (multiple, ongoing). Documented use of compromised victim systems for unauthorized cryptocurrency-mining as a residual-monetisation surface; per multi-vendor industry-forensic tracking. Attribution at inferred-strong per per-incident industry-forensic write-ups; broader cluster-attribution at confirmed.
- Worked examples for specific G13-mediated cryptocurrency-economy flows are pending v0.x and will live under
examples/once the per-incident sub-cluster attribution surface stabilises sufficiently for the OAK confirmed / inferred-strong distinction; the Pay2Key case is the highest-priority candidate.
Citations
[ofac2018samsam]— U.S. Department of the Treasury OFAC designation of Iranian nationals Ali Khorashadizadeh and Mohammad Ghorbaniyan for laundering SamSam ransomware proceeds, November 28, 2018; foundational sanctions-precedent for cryptocurrency-address-on-SDN-List enforcement architecture.[ofac2020apt39]— OFAC designation of Rana Intelligence Computing Company and APT39-affiliated individuals, September 17, 2020.[ofac2022irgcyber]— OFAC designation of multiple IRGC-affiliated individuals for ransomware-and-data-extortion operations, September 14, 2022.[cisa2022aa22055a]— Joint CISA / FBI / NSA / U.K. NCSC / U.S. Cyber Command cyber-security advisory AA22-055A on MuddyWater MOIS-attribution and TTPs, February 24, 2022.[cisa2022aa22257a]— Joint CISA / FBI / NSA / U.S. Cyber Command / U.S. Treasury / U.K. NCSC / ACSC / CCCS cyber-security advisory AA22-257A on IRGC-affiliated cyber-actor ransomware-and-data-extortion operations, September 14, 2022.[cisa2020aa20259a]— Joint CISA / FBI cyber-security advisory AA20-259A on Pioneer Kitten / Fox Kitten VPN-vulnerability exploitation, September 15, 2020.[fbi2024pioneerkittenflash]— FBI public Flash on Pioneer Kitten / Fox Kitten / Lemon Sandstorm activity, August 28, 2024.[checkpoint2020pay2key]— Check Point write-up on the November-to-December 2020 Pay2Key ransomware operation against Israeli targets.[clearsky2020pay2key]— ClearSky forensic write-up on Pay2Key Iranian-state-substrate attribution and on-chain links to Iranian-cryptocurrency-exchange counterparties.[mandiantapt35]— Mandiant APT35 / Newscaster / Charming Kitten tracker write-up.[microsoftmangosandstorm]— Microsoft Threat Intelligence on Mango Sandstorm (formerly Mercury) MuddyWater-equivalent tracking.[microsoftmintsandstorm]— Microsoft Threat Intelligence on Mint Sandstorm (formerly Phosphorus) Charming-Kitten-equivalent tracking.[microsoftlemonsandstorm]— Microsoft Threat Intelligence on Lemon Sandstorm Pioneer-Kitten-equivalent tracking.[crowdstrikepioneerkitten]— CrowdStrike Pioneer Kitten tracker write-up.
Discussion
On the attribution-strength split. The cluster-set-and-state-attribution layer (MuddyWater = MOIS; Charming Kitten / APT35 = IRGC-IO; Pioneer Kitten / Fox Kitten / Lemon Sandstorm = IRGC-affiliated) is confirmed — multiple OFAC designations across 2018-to-2024, multiple CISA / FBI / NSA / allied-government joint advisories, and sustained multi-vendor industry-forensic tracking converge. The per-incident sub-cluster partition between MuddyWater, Charming Kitten, and Pioneer Kitten within the broader Iranian-state-aligned cyber whole is operationally meaningful but is inferred-strong in many cases rather than confirmed; the public record does not always cleanly resolve which IRGC-or-MOIS sub-element ran a given cryptocurrency-economy-exposed incident. OAK contributors writing G13-attributed examples should preserve this split per-incident: attributing a campaign to "Iran / IRGC" or "Iran / MOIS" is confirmed-grade; attributing it specifically to MuddyWater (vs Charming Kitten vs Pioneer Kitten) requires either explicit Mandiant / Microsoft / CrowdStrike / vendor naming or technical-fingerprint-led sub-cluster identification.
On why OAK-G13 is cluster set rather than three separate Groups. Splitting MuddyWater, Charming Kitten, and Pioneer Kitten into three separate OAK-Gnn entries — analogous to how the DPRK-attributed cluster set is split into G01 (Lazarus) / G04 (DPRK IT-worker scheme) / G07 (APT43 / Kimsuky) / G08 (BlueNoroff) / G09 (Andariel) — would be the conventionally-rigorous structuring decision but is not warranted at v0.1. The DPRK split was warranted because (a) the DPRK clusters produce DPRK-scale aggregate cryptocurrency-theft volumes that justify granular per-cluster identity (per [chainalysis2024dprk], DPRK-attributed activity = 61% of all attacker-stolen value in 2024), and (b) the per-cluster mission boundary (regime-revenue-generating theft vs. self-funding-secondary espionage vs. IT-worker-placement vs. macOS-engineering-pipeline vs. ransomware-and-ICS) is operationally sharp enough to drive distinct defender-control regimes. The Iranian cluster set produces less than 1% of the DPRK aggregate cryptocurrency-economy footprint, the per-sub-cluster mission boundaries are less operationally sharp at the cryptocurrency-economy layer (all three share espionage-primary missions with cryptocurrency exposure as a secondary surface), and the per-incident sub-cluster partition is more often inferred-strong than confirmed. OAK-G13 documents the cluster set jointly at v0.1 and reserves the right to split into separate Groups in v0.x if warranted by sustained sub-cluster mission divergence at the cryptocurrency-economy layer.
On the cluster-boundary distinction with OAK-G01 / G04 / G07 / G08 / G09 (DPRK clusters). The DPRK and Iranian state-aligned cyber-cluster sets share state-aligned-and-financially-motivated operating models but differ along the aggregate-cryptocurrency-theft-volume, primary-mission-portfolio, operator-substrate-language, and sanctions-and-enforcement-surface axes. DPRK clusters produce industry-scale cryptocurrency-theft volumes ($1.34B / 47 incidents in 2024 = 61% of total attacker-stolen value per [chainalysis2024dprk]); Iranian clusters produce a substantially smaller cryptocurrency-economy footprint with notable concentration at sanctions-precedent events (the November 2018 SamSam-laundering OFAC designation) rather than at high-volume direct theft. DPRK clusters are organised around regime-revenue-generating theft (G01 / G08) and espionage-with-self-funding-cryptocurrency theft (G07) and IT-worker-placement-fraud (G04) and ransomware-and-ICS (G09); Iranian clusters are organised around espionage-primary with cryptocurrency exposure as a secondary monetisation surface and as a sanctions-evasion-adjacent surface. Defenders running anti-DPRK-cluster controls (engineering-staff social-engineering training, supply-chain build attestation, multisig-vendor diligence) leave the G13 surface only partially covered; G13 controls require additional coverage of (a) Iranian-economy cryptocurrency off-ramp counterparty screening, (b) cryptojacking-on-compromised-infrastructure detection, and (c) initial-access-broker-to-ransomware-affiliate sale pattern detection (Pioneer Kitten's hybrid model).
On the cluster-boundary distinction with OAK-G05 / G10 / G11 / G14 (Russian-language commercial-criminal RaaS clusters). G13 (Iranian state-aligned cyber operators) and the Russian-language commercial-criminal RaaS clusters differ along the state-aligned-vs-commercial-criminal axis, the operator-language-and-substrate axis, and the cryptocurrency-economy primary-mission axis. Pay2Key (the canonical Iranian-cluster-set ransomware-with-crypto-payment case) is structurally distinct from commercial RaaS in its short campaign window, target-concentration profile (Israeli-target concentration), and on-chain-counterparty profile (Iranian-cryptocurrency-exchange counterparties rather than Russian-language commercial-criminal off-ramp venues). Pioneer Kitten's hybrid initial-access-broker-to-ransomware-affiliate sale pattern produces the closest cluster-boundary overlap with the Russian-language affiliate-broker market — IRGC-affiliated-broker activity selling compromised access to commercial-RaaS affiliates is a documented inferred-strong-grade pattern per CISA AA20-259A — but the operator-substrate distinction (IRGC-affiliated vs Russian-language-commercial-criminal) and the downstream-laundering-profile distinction (Iranian-economy off-ramp vs Russian-language off-ramp) keep the clusters operationally separable.
On the relationship to OAK-G03 Russian laundering infrastructure. G03 (Russian laundering infrastructure, Garantex / Grinex / A7A5 lineage) and the Iranian-cluster-set-cryptocurrency-economy off-ramp surface are partially adjacent but not co-extensive. Iranian-cluster-set proceeds (per Pay2Key on-chain analysis and adjacent industry-forensic write-ups) tend to off-ramp through Iranian-cryptocurrency-exchange counterparties rather than through the Russian-language commercial-criminal off-ramp surface, with some documented overlap during Pioneer-Kitten-hybrid initial-access-broker-to-ransomware-affiliate engagements where the downstream ransomware-affiliate's laundering profile dominates. Defenders running OAK-G03 watchlists should expect limited overlap with G13-attributed inflows and should expect additional coverage requirements for Iranian-economy cryptocurrency off-ramp counterparty screening that is not produced by the G03 watchlist surface.
On v0.x evolution. G13's 2026+ trajectory will depend on (a) whether further OFAC designations against IRGC-affiliated and MOIS-affiliated cyber actors and infrastructure sustain the post-2018 sanctions-and-enforcement tempo; (b) whether sub-cluster mission divergence at the cryptocurrency-economy layer becomes sharp enough to warrant splitting MuddyWater / Charming Kitten / Pioneer Kitten into separate OAK-Gnn entries in v0.x; (c) whether per-incident sub-cluster attribution becomes more cleanly resolvable as forensic providers refine sub-cluster fingerprints; and (d) whether Iranian-cluster-set cryptocurrency-economy footprint scales materially in the 2026-and-after window relative to current sub-1% share. OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates. Future OAK Group additions in the Iranian-state-aligned cohort — additional named IRGC-or-MOIS sub-elements with cryptocurrency-economy exposure, or successor clusters — would warrant their own OAK-Gnn entries on the same per-cluster identity principle that motivated the DPRK G01 / G04 / G07 / G08 / G09 split.