Threat actor · OAK-G14
OAK-G14 — Cl0p / Clop Ransomware-and-Data-Extortion operation
Description
OAK-G14 is the Cl0p / Clop ransomware-and-data-extortion operation: a Russian-language operator network that, between February 2019 and the present, has been the most operationally durable of the major Russian-language ransomware-and-data-extortion clusters and has produced the canonical mass-exploitation-of-managed-file-transfer-products operational pattern in the public record. The cluster is genuinely distinct from prior OAK Groups along multiple axes: from OAK-G05 LockBit, OAK-G10 ALPHV / BlackCat, and OAK-G11 Black Basta along the operating-model axis (G14 pivoted to a data-extortion-only operating model from mid-2023 onward, in which encryption is no longer the load-bearing negotiation lever and the leaked-data-disclosure threat is the entire negotiation surface — structurally distinct from the encryption-and-data-extortion double-extortion model that defines G05, G10, and G11) and along the initial-access-vector axis (G14's signature operational pattern is exclusive-vendor mass-exploitation of zero-day vulnerabilities in managed-file-transfer products, producing multi-thousand-organisation-victim cohorts from a single zero-day, distinct from the affiliate-distributed broad-spectrum-intrusion model of G05, G10, and G11); from OAK-G12 Scattered Spider along the operating-brand-vs-affiliate-collective axis (G14 is a Russian-language operating-brand cluster; G12 is an English-speaking affiliate-collective); and from OAK-G07 Kimsuky and OAK-G13 Iranian-crypto-operators along the commercial-criminal-vs-state-aligned axis. Cl0p's inclusion in OAK is not because it is a crypto-native operator — its targets are overwhelmingly traditional-enterprise IT estates and downstream multi-thousand-organisation MFT-product-deployment cohorts — but because cryptocurrency is the load-bearing payment-and-laundering rail of the entire ransomware-and-data-extortion business model, because the June 2023 MOVEit campaign is the canonical mass-extortion worked example in the public record (affecting more than 2,500 organisations from a single CVE-2023-34362 zero-day, per FBI / CISA AA23-158A and per Coveware aggregate tracking), and because the 2023 data-extortion-only pivot is a operating-model-novelty marker in the ransomware-extortion ecosystem that defenders, regulators, and exchanges should treat as a sustained behaviour pattern rather than a one-off.
The operational model is a Russian-language operator-cohort-led ransomware-and-data-extortion operation with several cluster-distinctive features. Cl0p emerged from the broader TA505 operator-cohort substrate (Proofpoint-tracked TA505 activity dates to 2014 and includes Dridex banking-malware distribution, FlawedAmmyy RAT campaigns, and pre-Cl0p ransomware activity); the Cl0p-branded encryptor first appeared in February-to-March 2019 and was used through mid-2023 in a conventional encryption-and-data-extortion double-extortion model. The cluster's first mass-exploitation-of-MFT-products campaign was the December 2020-to-early-2021 Accellion FTA campaign, exploiting the legacy Accellion File Transfer Appliance product across approximately 100 customer organisations (Accellion was end-of-life at the time of the campaign and Cl0p targeted the residual-deployment cohort); the second was the February 2023 GoAnywhere MFT campaign exploiting CVE-2023-0669 across approximately 130 customer organisations; the canonical third was the June 2023 MOVEit Transfer campaign exploiting CVE-2023-34362 across more than 2,500 organisations and affecting an estimated 65-million-plus individual records, the largest-by-organisation-count mass-extortion campaign in the public record. From mid-2023 onward, coinciding with the MOVEit campaign, Cl0p pivoted to a data-extortion-only operating model in which encryption is no longer deployed and the negotiation surface is entirely the leaked-data-disclosure threat — a structural shift that reduced the cluster's intrusion-and-deployment-cost profile, eliminated the encryption-recovery negotiation lever (and the corresponding decryptor-key-distribution operational risk), and concentrated operator value-extraction on the data-disclosure-threat-and-leak-site-pressure surface. Per Coveware aggregate tracking, the data-extortion-only pivot produced lower per-victim ransom-payment averages than the prior encryption-and-data-extortion model but a higher victim-count throughput and higher aggregate extortion-revenue volume across the 2023-to-2024 window. The cluster's operator cohort is Russian-language and overlaps substantially with the broader Russian-language commercial-criminal ecosystem; the June 2021 Ukrainian Cyber Police arrests of multiple Cl0p-affiliated individuals in coordination with U.S. and South Korean law enforcement degraded but did not extinguish the cluster, and Cl0p-branded operations resumed within months of the arrest tempo.
The cluster's defender-relevant signature is upstream-extraction-cluster with confirmed-grade public attribution at the OFAC-and-CISA-advisory layer, signature mass-exploitation-of-MFT-products operational pattern, and a mid-2023 data-extortion-only operating-model pivot that is itself a defender-relevant marker for the broader ransomware-and-data-extortion ecosystem evolution. The June 2023 MOVEit campaign is the canonical worked example of mass-extortion-via-MFT-zero-day: a single CVE-2023-34362 zero-day in Progress Software's MOVEit Transfer product was exploited at scale across approximately 72 hours from late May into early June 2023, producing more than 2,500 named-victim organisations across U.S. federal-government agencies (Department of Energy, Department of Health and Human Services, Department of Homeland Security, multiple state-government agencies), large enterprise (Shell, Siemens, Sony, multiple U.K. financial-services firms), educational institutions, and a long tail of MFT-deployed enterprise targets, with downstream-affected-individual records exceeding 65 million per multiple aggregate tracking sources. The campaign produced the largest single-campaign cyber-incident-disclosure-cohort in U.S. federal-government regulatory history and produced sustained CISA / FBI / OFAC enforcement-and-advisory tempo through 2023-and-2024. The August-to-October 2023 follow-on Cl0p TeamCity zero-day campaign (CVE-2023-42793) extended the mass-exploitation operational pattern beyond MFT products into the broader software-supply-chain attack surface; the late-2024 Cleo CVE-2024-50623 / CVE-2024-55956 mass-exploitation campaign attributed to Cl0p per multiple industry-forensic write-ups extended the pattern further. Defenders running anti-G14 control sets should expect the MFT-product-or-adjacent-enterprise-software zero-day mass-exploitation operational pattern to continue, and should treat managed-file-transfer-product defense (Accellion FTA, GoAnywhere, MOVEit, Cleo, IBM Aspera, JSCAPE, and adjacent products) as a Cl0p-specific high-priority control surface in addition to the broader anti-ransomware-and-data-extortion control set.
Targeting profile
OAK-G14's victim profile is enterprise-IT-and-MFT-product-deployment-cohort-led, with sector concentration across U.S. federal and state government, financial services, healthcare, manufacturing, and educational institutions, and with a campaign-cohort-driven victim-distribution pattern rather than a per-victim-affiliate-selected pattern that defines other RaaS clusters:
- U.S. federal and state government agencies — multiple U.S. federal-government agencies affected by the June 2023 MOVEit campaign (Department of Energy, HHS, DHS, multiple branches of the U.S. military), multiple U.S. state-government agencies (notably state motor-vehicle and Medicaid agencies); sustained CISA / FBI advisory tempo through 2023-and-2024 reflects this targeting profile.
- Financial-services and insurance-sector firms — multiple U.S. and U.K. banks and financial-services firms affected by MOVEit campaign (TIAA, Prudential, U.S. financial-services-sector pension-administration firms via PBI Research Services); financial-sector targeting was a stated escalation factor in the OFAC June 2023 designations.
- Healthcare-sector firms — multiple U.S. healthcare-sector firms affected by MOVEit campaign (HHS, multiple state-Medicaid agencies, hospital systems); healthcare-sector targeting is consistent with broader Cl0p operating-pattern profile.
- Educational institutions — multiple U.S. and U.K. universities affected by MOVEit campaign (notably the U.S. National Student Clearinghouse exposure that affected approximately 900 educational institutions downstream); the June 2023 MOVEit campaign produced the largest single educational-sector cyber-incident-disclosure-cohort in U.S. regulatory history.
- Large enterprise across all sectors — Shell, Siemens, Sony (multiple), and a long tail of MFT-deployed enterprise targets; the MFT-product-deployment-cohort targeting pattern produces a sector-distribution that is more uniform across sectors than any affiliate-distributed RaaS profile.
- Cryptocurrency-industry firms as occasional targets — present but not the dominant target class; G14 is enterprise-extortion-led, not crypto-native-extraction-led.
- Downstream cryptocurrency users — only as secondary victims of the laundering rails the operation depends on.
Observed Techniques
OAK v0.1's Tactic catalog is on-chain-extraction-focused; Cl0p's intrusion surface (off-chain mass-exploitation of MFT-product zero-days, custom web-shell deployment for data-exfiltration, and post-mid-2023 data-exfiltration-without-encryption operational style) sits outside that scope and is documented under external Group ID G0092 in the conventional cyber-threat-intel taxonomy. The on-chain Techniques observed in OAK-G14-attributable activity are concentrated on the payment-and-laundering side:
- OAK-T7.001 (Mixer-Routed Hop) — observed as a partial / earlier-stage component of the broader Cl0p laundering chain, with usage of Bitcoin mixers declining sharply across 2022-to-2024 in step with the sector-wide post-Tornado-Cash-designation decline; per
[chainalysis2025ransomware]mixer-share of ransomware-laundering volume fell substantially across 2023-to-2024 as a sector-wide effect and Cl0p followed the trend. - OAK-T7.002 (CEX Deposit-Address Layering) — the canonical post-2023 Cl0p off-ramp, with affiliate-controlled deposit-address activity at non-KYC, lax-KYC, and Russian-language commercial-criminal off-ramp venues a recurring industry-forensic signature; per Chainalysis and TRM Labs aggregate tracking, Cl0p downstream-laundering profile shows substantial overlap with the OAK-G03 Russian-language commercial-criminal off-ramp surface.
- OAK-T7.003 (Cross-Asset / Cross-Chain Laundering) — observed in Cl0p laundering chains, with Bitcoin-to-stablecoin and Bitcoin-to-Monero conversion legs documented per industry-forensic write-ups.
- OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by Mandiant, Microsoft, Chainalysis, TRM Labs, and Coveware to maintain Cl0p affiliate-cluster identification across encryptor-version rotations, across the mid-2023 data-extortion-only operating-model pivot, and across the post-2024 mass-exploitation-campaign-rotation surface (MOVEit → TeamCity → Cleo). The persistence of Bitcoin-funder-cluster identity across the cluster's 2019-to-2025 operating window — including across the multi-jurisdiction June 2021 Ukrainian-Cyber-Police-arrest disruption — is among the strongest indicators of operator continuity in the ransomware sector.
- OAK-T8.002 (Cross-Chain Operator Continuity) — observed across mass-exploitation-campaign rotations and across the data-extortion-only operating-model pivot.
- Adjacent / pre-incident vectors not in OAK v0.1 scope: off-chain initial access via mass-exploitation of MFT-product zero-days (Accellion FTA CVE-2021-27101 / CVE-2021-27102 / CVE-2021-27103 / CVE-2021-27104; GoAnywhere MFT CVE-2023-0669; MOVEit Transfer CVE-2023-34362; TeamCity CVE-2023-42793; Cleo CVE-2024-50623 / CVE-2024-55956), custom web-shell deployment (LEMURLOOT / "human2.aspx" web shell for the MOVEit campaign), and post-mid-2023 data-exfiltration-without-encryption operational style; these are the canonical Cl0p intrusion vectors and are documented in CISA AA23-158A, AA23-039A, and multi-vendor industry-forensic tracking.
- Operating-model-novelty marker not in OAK v0.1 scope: the mid-2023 data-extortion-only pivot is an operating-model novelty in the ransomware-and-data-extortion ecosystem that does not map cleanly onto any on-chain Tactic and is not a credible candidate for OAK-T inclusion at v0.1. It is documented here as an operator-behaviour evolution because (a) it is the first publicly-documented case of a high-volume ransomware operator pivoting to a data-extortion-only operating model at scale, (b) successor and adjacent clusters have adopted variants of the data-extortion-only pattern (Karakurt, BianLian, RansomHouse), and (c) defender control-set design for ransomware-and-data-extortion response now needs to assume that encryption-deployment is not the only operating-model and data-disclosure-threat-only-extortion is part of the threat-actor toolkit.
Observed Examples
Worked examples in examples/:
examples/2023-06-moveit-clop-campaign.md— MOVEit Transfer mass-extortion campaign; ~2,500 victim organisations; estimated $75M–$100M+ total ransom volume; canonical OAK-G14 worked example.
The high-salience public-record events anchoring the cluster (narrative — see worked example above for the canonical entry):
- Accellion FTA mass-exploitation campaign (December 2020-to-early-2021). Cl0p's first mass-exploitation-of-MFT-products campaign, exploiting the legacy Accellion File Transfer Appliance product across approximately 100 customer organisations using CVE-2021-27101 / CVE-2021-27102 / CVE-2021-27103 / CVE-2021-27104. Established the cluster's signature operational pattern. Attribution at confirmed per Mandiant FIN11 and CISA tracking.
- GoAnywhere MFT mass-exploitation campaign (February 2023). Cl0p's second mass-exploitation-of-MFT-products campaign, exploiting Fortra's GoAnywhere MFT product across approximately 130 customer organisations using CVE-2023-0669; produced multiple high-profile victims including Community Health Systems and Procter & Gamble. Attribution at confirmed.
- CISA / FBI AA23-039A "#StopRansomware: CLOP Ransomware" advisory (February 8, 2023). Joint CISA / FBI cyber-security advisory characterising Cl0p TTPs across the 2019-to-2023 operating window and the cluster's MFT-product mass-exploitation operational signature (
[cisa2023aa23039aclop]). Attribution at confirmed. - MOVEit Transfer mass-exploitation campaign (May 27, 2023-to-present). Cl0p's canonical mass-exploitation-of-MFT-products campaign, exploiting Progress Software's MOVEit Transfer product across more than 2,500 named-victim organisations using CVE-2023-34362, with the LEMURLOOT custom web-shell deployed for data-exfiltration; produced downstream-affected-individual records exceeding 65 million and the largest single-campaign cyber-incident-disclosure-cohort in U.S. federal-government regulatory history. Sustained CISA / FBI / OFAC enforcement-and-advisory tempo through 2023-and-2024. Attribution at confirmed.
- CISA / FBI AA23-158A "CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability" advisory (June 7, 2023). Joint CISA / FBI / NSA / U.S. Cyber Command cyber-security advisory characterising the MOVEit campaign and Cl0p TTPs (
[cisa2023aa23158aclop]). Attribution at confirmed. - OFAC June 2023 designations of Cl0p-affiliated Russian nationals. OFAC SDN designations of multiple Cl0p-affiliated Russian nationals in June 2023, producing a cluster-attribution-and-named-individual-attribution layer beyond the prior AA23-039A and AA23-158A advisories (
[ofac2023clopaffiliates]). Attribution at confirmed. - June 2021 Ukrainian Cyber Police arrests. Coordinated U.S. / South Korean / Ukrainian arrests of multiple Cl0p-affiliated individuals in Kyiv in June 2021, with seized infrastructure and extradition activity (
[ukrcyberpolice2021clop]). Attribution at confirmed. The arrests degraded but did not extinguish the cluster; Cl0p-branded operations resumed within months. - Cl0p mid-2023 data-extortion-only operating-model pivot. From mid-2023 onward, Cl0p pivoted from the encryption-and-data-extortion double-extortion model to a data-extortion-only operating model in which encryption is no longer deployed and the negotiation surface is entirely the leaked-data-disclosure threat. Documented in industry-forensic tracking as an operating-model novelty marker. Attribution at confirmed (the pivot is observable in the public-record campaign data); the pivot's downstream effect on cluster economics and on adjacent-cluster behaviour is inferred-strong.
- Cleo mass-exploitation campaign (late-2024). Cl0p-attributed mass-exploitation campaign exploiting Cleo's enterprise-software products using CVE-2024-50623 / CVE-2024-55956; extending the cluster's MFT-and-adjacent-enterprise-software mass-exploitation operational pattern beyond MOVEit. Attribution at inferred-strong per multiple industry-forensic write-ups.
- Aggregate Cl0p metrics from CISA / FBI / OFAC reporting (>2,500 MOVEit-campaign victims; multi-year operational continuity from 2019-to-present; sustained leak-site operation) and from
[chainalysis2025ransomware]and adjacent industry-forensic aggregate tracking (>$100M in confirmed extortion proceeds across the cluster's operating window; top-tier of ransomware-and-data-extortion volume per the 2023-and-2024 Chainalysis ransomware reports). - Worked examples for specific G14-mediated ransom-payment laundering flows are pending v0.x and will live under
examples/once the per-incident attribution surface stabilises sufficiently for the OAK confirmed / inferred-strong distinction; the MOVEit campaign is the highest-priority candidate.
Citations
[cisa2023aa23158aclop]— Joint CISA / FBI / NSA / U.S. Cyber Command cyber-security advisory AA23-158A on Cl0p MOVEit campaign, June 7, 2023.[cisa2023aa23039aclop]— Joint CISA / FBI cyber-security advisory AA23-039A "#StopRansomware: CLOP Ransomware," February 8, 2023.[ofac2023clopaffiliates]— U.S. Department of the Treasury OFAC June 2023 designations of multiple Cl0p-affiliated Russian nationals.[ukrcyberpolice2021clop]— Ukrainian Cyber Police announcement of June 2021 arrests of multiple Cl0p-affiliated individuals in coordination with U.S. and South Korean law enforcement.[mandiantfin11]— Mandiant FIN11 / TA505 / Cl0p tracker write-up on operator-cohort attribution.[microsoftlacetempest]— Microsoft Threat Intelligence on Lace Tempest Cl0p-affiliated MOVEit-campaign-running sub-cluster.[coveware2023moveit]— Coveware retrospective on the MOVEit campaign victim-cohort and ransom-payment aggregates.[chainalysis2023clop]— Chainalysis forensic write-up of Cl0p downstream-laundering profile and MOVEit-campaign on-chain payment tracing.[trmlabs2023moveit]— TRM Labs forensic write-up of MOVEit-campaign Bitcoin payment tracing.[chainalysis2025ransomware]— Chainalysis 2024-recap ransomware report (referenced from G05 / G10 / G11 documentation as well); documents Cl0p aggregate proceeds and the data-extortion-only pivot.[ofac2022tornado]— sector-wide mixer-laundering enforcement context (referenced for the post-2022 ransomware-mixer-share decline, not for shared cluster identity).
Discussion
On the attribution-strength split. The Cl0p operator-cluster attribution is confirmed at the OFAC-and-CISA-advisory layer — the June 2023 OFAC SDN designations of multiple Cl0p-affiliated Russian nationals, the June 2023 CISA / FBI / NSA / U.S. Cyber Command AA23-158A advisory on the MOVEit campaign, the February 2023 CISA / FBI AA23-039A advisory on Cl0p TTPs, and the June 2021 Ukrainian Cyber Police arrests of multiple Cl0p-affiliated individuals together produce a confirmed-grade public-attribution surface. Attribution that specific affiliate operators are tied to specific real-world identities beyond the OFAC-designated nationals is inferred-strong per Mandiant FIN11 / TA505 / Cl0p sub-cluster tracking. OAK contributors writing G14-attributed examples should preserve this attribution-strength split per-incident.
On why OAK-G14 is operating-brand cluster rather than TA505 operator-cohort. Naming this Group entry "TA505" would have framed the cluster at the broader operator-cohort level (TA505-attributed activity dates to 2014 and includes pre-Cl0p Dridex banking-malware distribution and FlawedAmmyy RAT campaigns), but would mis-frame the operating-model continuity model in the same way that the analogous framing would mis-frame OAK-G05 / G10 / G11. The Cl0p-branded ransomware-and-data-extortion operation is a sub-activity within the broader TA505 operator-cohort, and the Cl0p-branded operating-model continuity from 2019-to-present (across the MFT-mass-exploitation campaigns and across the mid-2023 data-extortion-only pivot) is the cleaner persistent identity than the broader TA505-cohort substrate. By the same logic, naming the Group at the individual-affiliate level would mis-frame the operating-brand-persistence pattern that defines the cluster.
On the cluster-boundary distinction with OAK-G05 / G10 / G11 (Russian-language operating-brand RaaS clusters). G05 (LockBit), G10 (ALPHV), G11 (Black Basta), and G14 (Cl0p) share Russian-language operator substrate and operate ransomware-and-data-extortion business models, but differ along the initial-access-vector axis (G14 is mass-exploitation-of-MFT-products-led; G05 / G10 / G11 are affiliate-distributed-broad-spectrum-intrusion-led), the operating-model axis (G14 pivoted to data-extortion-only from mid-2023 onward; G05 / G10 / G11 retain encryption-and-data-extortion double-extortion), the attribution-surface axis (G14 is confirmed-by-OFAC-SDN-designations-of-affiliates plus CISA-advisories; structurally adjacent to G05's confirmed-by-OFAC-and-DOJ surface and structurally distinct from G10's confirmed-by-disruption-and-indictment surface and G11's confirmed-by-CISA-advisory surface), and the exit-dynamic axis (G14 has not exited and remains operationally active as of v0.1; G05 was disrupted via Operation Cronos; G10 exited via operator-side scam; G11 internal-wound-down following internal-chats leak). Defenders running anti-G14 control sets should expect substantial overlap with anti-G05 / G10 / G11 control-set design at the off-chain-laundering-and-ransom-payment-flow layer (Russian-language commercial-criminal off-ramp profile) but should expect distinct on-chain attribution surfaces and distinct off-chain intrusion-vector control requirements (MFT-product defense as a Cl0p-specific high-priority control surface).
On the cluster-boundary distinction with OAK-G12 Scattered Spider. G14 (Cl0p) and G12 (Scattered Spider) are both ransomware-and-data-extortion-related clusters but differ along the operator-substrate axis (G14 is Russian-language operating-brand; G12 is English-speaking affiliate-collective), the initial-access-vector axis (G14 is mass-exploitation-of-MFT-products-led; G12 is social-engineering-and-help-desk-attack-led), and the operating-model axis (G14 runs its own ransomware-and-data-extortion infrastructure; G12 is an affiliate of multiple RaaS brands). The two clusters have not been documented as collaborating operationally on the public record and operate in distinct operator-substrate ecosystems.
On the data-extortion-only pivot as operating-model evolution. The mid-2023 Cl0p data-extortion-only pivot is an operating-model-novelty marker that defender control-set design needs to internalise even though it is not an OAK-T-classifiable on-chain Technique. The operating-model-surface in ransomware-and-data-extortion has expanded across 2023-to-2025 from encryption-and-data-extortion double-extortion to data-extortion-only operating models (Cl0p, Karakurt, BianLian, RansomHouse), to leaked-data-disclosure-with-press-pressure operating models, and to regulator-disclosure-regime weaponisation operating models (the OAK-G10 ALPHV SEC-filing tactic against MeridianLink, with Cl0p adopting variants of the regulator-disclosure pressure tactic). OAK should not absorb operating-model-novelty into its on-chain Tactic catalog at v0.1 — it would dilute the on-chain framing — but G14's documentation should preserve the marker for downstream consumers building incident-response runbooks. The defender takeaway is that ransomware-and-data-extortion negotiation in 2024-and-after operates under a substantively different operating-model and disclosure-regime threat model than it did in 2022, and counter-party-screening control sets need to assume that data-extortion-only and regulator-disclosure-pressure operating-models are part of the threat-actor toolkit.
On the relationship to OAK-G03 Russian laundering infrastructure. G03 (Russian laundering infrastructure, Garantex / Grinex / A7A5 lineage) was a documented downstream venue for some fraction of Cl0p proceeds, with the G14 / G03 chain showing substantial overlap per Chainalysis and TRM Labs aggregate tracking. The cluster's Russian-language commercial-criminal off-ramp profile shows distribution across multiple non-KYC and lax-KYC venues with concentration at OAK-G03-cluster venues during the 2022-to-2024 window. Defenders running OAK-G03 watchlists should expect substantial overlap with G14-attributed inflows.
On v0.x evolution. G14's 2026+ trajectory will depend on (a) whether further OFAC designations of Cl0p-affiliated individuals or infrastructure sustain the post-June-2023 enforcement tempo; (b) whether the cluster continues the mass-exploitation-of-MFT-and-adjacent-enterprise-software operational pattern (the late-2024 Cleo campaign suggests sustained operational durability through 2025); (c) whether the data-extortion-only operating-model pivot persists or whether the cluster reverts to encryption-and-data-extortion double-extortion; (d) whether a worked example of the MOVEit campaign is added under examples/ once the per-flow attribution surface stabilises sufficiently; and (e) whether successor or splinter activity (e.g., spin-off operating brands within the broader TA505 operator-cohort substrate) emerges. OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates. Future OAK Group additions in the ransomware-and-data-extortion sector — additional Conti-successor brands, RansomHub as a standalone successor-brand entry, dedicated data-extortion-only clusters (Karakurt, BianLian, RansomHouse) — would each warrant their own OAK-Gnn entry rather than extension of G05 / G10 / G11 / G14, on the same per-cluster identity principle.