OAK — OnChain Attack Knowledge

Threat actor · OAK-G14

OAK-G14 — Cl0p / Clop Ransomware-and-Data-Extortion operation

Aliases
Cl0p (operating brand on Russian-language criminal forums and the cluster's Tor-hosted "CL0P^_- LEAKS" leak site, 2019 → present, with the zero in "Cl0p" rendered with a literal numeral in the cluster's own self-identification and frequently transliterated as "Clop" in industry-forensic and regulatory write-ups), TA505 (Proofpoint tracker name for the broader operator-cohort, with TA505-attributed activity dating to 2014 and the Cl0p-branded ransomware operation a sub-activity of the TA505 cohort from 2019 onward), FIN11 (Mandiant tracker name for the financially-motivated activity cohort overlapping with TA505 / Cl0p; Mandiant tracking documents the FIN11 / Cl0p relationship as overlapping but not identical), Lace Tempest (Microsoft tracker name for the Cl0p-affiliated MOVEit-campaign-running sub-cluster), DEV-0950 (Microsoft legacy tracker), Hive0065 (IBM X-Force), and the affiliate cohort named in the June 2023 OFAC and FBI / CISA AA23-158A advisories. For OAK-G14 purposes the cluster is the Cl0p ransomware-and-data-extortion operation — the core operator network behind the Cl0p encryptor (and from 2023 onward, the Cl0p data-extortion-only operating model), the affiliate-management infrastructure, and the leak-site operation — considered jointly with the TA505 operator cohort substrate from which Cl0p emerged. The cluster's signature operational pattern is mass-exploitation campaigns against managed-file-transfer (MFT) products: the December 2020-to-early-2021 Accellion FTA campaign, the February 2023 GoAnywhere MFT campaign, and the canonical June 2023 MOVEit Transfer mass-exploitation campaign (CVE-2023-34362), each of which produced a multi-thousand-organisation-victim cohort.
First observed in crypto
February-to-March 2019 (Cl0p-branded encryptor first observed on Russian-language criminal forums; the RaaS / ransomware operating model with Bitcoin-denominated ransom payments has been the operational default since inception, with the cluster pivoting to a data-extortion-only operating model from mid-2023 onward in which encryption is no longer deployed and the negotiation surface is entirely the leaked-data-disclosure threat).
Attribution status
confirmed at the cluster-and-named-affiliate level — U.S. Department of the Treasury OFAC June 2023 designations of multiple Cl0p-affiliated Russian nationals ([ofac2023clopaffiliates]); CISA / FBI / NSA / U.S. Cyber Command joint cyber-security advisory AA23-158A "CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability," June 7, 2023 ([cisa2023aa23158aclop]); CISA / FBI joint cyber-security advisory AA23-039A "#StopRansomware: CLOP Ransomware," February 8, 2023 ([cisa2023aa23039aclop]); June 2021 Ukrainian Cyber Police arrests of multiple Cl0p-affiliated individuals in coordination with the U.S. and South Korean law enforcement ([ukrcyberpolice2021clop]); U.S. Department of State Rewards for Justice $10M reward for information on Cl0p leadership and affiliates (consistent with the broader RfJ ransomware-leadership reward architecture); sustained multi-vendor industry-forensic corroboration (Mandiant, Microsoft, CrowdStrike, Sophos, Recorded Future, Coveware, Chainalysis, TRM Labs, Sangfor) characterising the encryptor lineage, the TA505 / FIN11 operator-cohort substrate, the data-extortion-only pivot of mid-2023, and the mass-exploitation operational signature. Attribution that specific ransom-payment flows or data-extortion-payment flows trace to specific affiliate wallets within the Cl0p cluster is inferred-strong from industry forensic providers; per Coveware and Chainalysis aggregate tracking, Cl0p-attributable extortion proceeds across the cluster's operating window exceed $100M and place the cluster in the top-tier of ransomware-and-data-extortion volume per the 2023-and-2024 Chainalysis ransomware reports ([chainalysis2025ransomware]).
Active
yes as of v0.1 — Cl0p-branded extortion activity continued through 2024-and-2025 with continued mass-exploitation campaigns against managed-file-transfer and adjacent enterprise-software products (notably the late-2024 Cleo CVE-2024-50623 / CVE-2024-55956 mass-exploitation campaign attributed to Cl0p per multiple industry-forensic write-ups), sustained leak-site operation, and continued ransom-payment flow tracked by industry-forensic providers. The cluster has been the most operationally durable of the major Russian-language ransomware-and-data-extortion clusters across the 2022-to-2025 window, with no public-record exit-scam (unlike OAK-G10 ALPHV), no law-enforcement-disruption-and-OFAC-listing-of-cluster-wallets event (unlike OAK-G05 LockBit), and no internal-wind-down-following-internal-chats-leak event (unlike OAK-G11 Black Basta).

Description

OAK-G14 is the Cl0p / Clop ransomware-and-data-extortion operation: a Russian-language operator network that, between February 2019 and the present, has been the most operationally durable of the major Russian-language ransomware-and-data-extortion clusters and has produced the canonical mass-exploitation-of-managed-file-transfer-products operational pattern in the public record. The cluster is genuinely distinct from prior OAK Groups along multiple axes: from OAK-G05 LockBit, OAK-G10 ALPHV / BlackCat, and OAK-G11 Black Basta along the operating-model axis (G14 pivoted to a data-extortion-only operating model from mid-2023 onward, in which encryption is no longer the load-bearing negotiation lever and the leaked-data-disclosure threat is the entire negotiation surface — structurally distinct from the encryption-and-data-extortion double-extortion model that defines G05, G10, and G11) and along the initial-access-vector axis (G14's signature operational pattern is exclusive-vendor mass-exploitation of zero-day vulnerabilities in managed-file-transfer products, producing multi-thousand-organisation-victim cohorts from a single zero-day, distinct from the affiliate-distributed broad-spectrum-intrusion model of G05, G10, and G11); from OAK-G12 Scattered Spider along the operating-brand-vs-affiliate-collective axis (G14 is a Russian-language operating-brand cluster; G12 is an English-speaking affiliate-collective); and from OAK-G07 Kimsuky and OAK-G13 Iranian-crypto-operators along the commercial-criminal-vs-state-aligned axis. Cl0p's inclusion in OAK is not because it is a crypto-native operator — its targets are overwhelmingly traditional-enterprise IT estates and downstream multi-thousand-organisation MFT-product-deployment cohorts — but because cryptocurrency is the load-bearing payment-and-laundering rail of the entire ransomware-and-data-extortion business model, because the June 2023 MOVEit campaign is the canonical mass-extortion worked example in the public record (affecting more than 2,500 organisations from a single CVE-2023-34362 zero-day, per FBI / CISA AA23-158A and per Coveware aggregate tracking), and because the 2023 data-extortion-only pivot is a operating-model-novelty marker in the ransomware-extortion ecosystem that defenders, regulators, and exchanges should treat as a sustained behaviour pattern rather than a one-off.

The operational model is a Russian-language operator-cohort-led ransomware-and-data-extortion operation with several cluster-distinctive features. Cl0p emerged from the broader TA505 operator-cohort substrate (Proofpoint-tracked TA505 activity dates to 2014 and includes Dridex banking-malware distribution, FlawedAmmyy RAT campaigns, and pre-Cl0p ransomware activity); the Cl0p-branded encryptor first appeared in February-to-March 2019 and was used through mid-2023 in a conventional encryption-and-data-extortion double-extortion model. The cluster's first mass-exploitation-of-MFT-products campaign was the December 2020-to-early-2021 Accellion FTA campaign, exploiting the legacy Accellion File Transfer Appliance product across approximately 100 customer organisations (Accellion was end-of-life at the time of the campaign and Cl0p targeted the residual-deployment cohort); the second was the February 2023 GoAnywhere MFT campaign exploiting CVE-2023-0669 across approximately 130 customer organisations; the canonical third was the June 2023 MOVEit Transfer campaign exploiting CVE-2023-34362 across more than 2,500 organisations and affecting an estimated 65-million-plus individual records, the largest-by-organisation-count mass-extortion campaign in the public record. From mid-2023 onward, coinciding with the MOVEit campaign, Cl0p pivoted to a data-extortion-only operating model in which encryption is no longer deployed and the negotiation surface is entirely the leaked-data-disclosure threat — a structural shift that reduced the cluster's intrusion-and-deployment-cost profile, eliminated the encryption-recovery negotiation lever (and the corresponding decryptor-key-distribution operational risk), and concentrated operator value-extraction on the data-disclosure-threat-and-leak-site-pressure surface. Per Coveware aggregate tracking, the data-extortion-only pivot produced lower per-victim ransom-payment averages than the prior encryption-and-data-extortion model but a higher victim-count throughput and higher aggregate extortion-revenue volume across the 2023-to-2024 window. The cluster's operator cohort is Russian-language and overlaps substantially with the broader Russian-language commercial-criminal ecosystem; the June 2021 Ukrainian Cyber Police arrests of multiple Cl0p-affiliated individuals in coordination with U.S. and South Korean law enforcement degraded but did not extinguish the cluster, and Cl0p-branded operations resumed within months of the arrest tempo.

The cluster's defender-relevant signature is upstream-extraction-cluster with confirmed-grade public attribution at the OFAC-and-CISA-advisory layer, signature mass-exploitation-of-MFT-products operational pattern, and a mid-2023 data-extortion-only operating-model pivot that is itself a defender-relevant marker for the broader ransomware-and-data-extortion ecosystem evolution. The June 2023 MOVEit campaign is the canonical worked example of mass-extortion-via-MFT-zero-day: a single CVE-2023-34362 zero-day in Progress Software's MOVEit Transfer product was exploited at scale across approximately 72 hours from late May into early June 2023, producing more than 2,500 named-victim organisations across U.S. federal-government agencies (Department of Energy, Department of Health and Human Services, Department of Homeland Security, multiple state-government agencies), large enterprise (Shell, Siemens, Sony, multiple U.K. financial-services firms), educational institutions, and a long tail of MFT-deployed enterprise targets, with downstream-affected-individual records exceeding 65 million per multiple aggregate tracking sources. The campaign produced the largest single-campaign cyber-incident-disclosure-cohort in U.S. federal-government regulatory history and produced sustained CISA / FBI / OFAC enforcement-and-advisory tempo through 2023-and-2024. The August-to-October 2023 follow-on Cl0p TeamCity zero-day campaign (CVE-2023-42793) extended the mass-exploitation operational pattern beyond MFT products into the broader software-supply-chain attack surface; the late-2024 Cleo CVE-2024-50623 / CVE-2024-55956 mass-exploitation campaign attributed to Cl0p per multiple industry-forensic write-ups extended the pattern further. Defenders running anti-G14 control sets should expect the MFT-product-or-adjacent-enterprise-software zero-day mass-exploitation operational pattern to continue, and should treat managed-file-transfer-product defense (Accellion FTA, GoAnywhere, MOVEit, Cleo, IBM Aspera, JSCAPE, and adjacent products) as a Cl0p-specific high-priority control surface in addition to the broader anti-ransomware-and-data-extortion control set.

Targeting profile

OAK-G14's victim profile is enterprise-IT-and-MFT-product-deployment-cohort-led, with sector concentration across U.S. federal and state government, financial services, healthcare, manufacturing, and educational institutions, and with a campaign-cohort-driven victim-distribution pattern rather than a per-victim-affiliate-selected pattern that defines other RaaS clusters:

  • U.S. federal and state government agencies — multiple U.S. federal-government agencies affected by the June 2023 MOVEit campaign (Department of Energy, HHS, DHS, multiple branches of the U.S. military), multiple U.S. state-government agencies (notably state motor-vehicle and Medicaid agencies); sustained CISA / FBI advisory tempo through 2023-and-2024 reflects this targeting profile.
  • Financial-services and insurance-sector firms — multiple U.S. and U.K. banks and financial-services firms affected by MOVEit campaign (TIAA, Prudential, U.S. financial-services-sector pension-administration firms via PBI Research Services); financial-sector targeting was a stated escalation factor in the OFAC June 2023 designations.
  • Healthcare-sector firms — multiple U.S. healthcare-sector firms affected by MOVEit campaign (HHS, multiple state-Medicaid agencies, hospital systems); healthcare-sector targeting is consistent with broader Cl0p operating-pattern profile.
  • Educational institutions — multiple U.S. and U.K. universities affected by MOVEit campaign (notably the U.S. National Student Clearinghouse exposure that affected approximately 900 educational institutions downstream); the June 2023 MOVEit campaign produced the largest single educational-sector cyber-incident-disclosure-cohort in U.S. regulatory history.
  • Large enterprise across all sectors — Shell, Siemens, Sony (multiple), and a long tail of MFT-deployed enterprise targets; the MFT-product-deployment-cohort targeting pattern produces a sector-distribution that is more uniform across sectors than any affiliate-distributed RaaS profile.
  • Cryptocurrency-industry firms as occasional targets — present but not the dominant target class; G14 is enterprise-extortion-led, not crypto-native-extraction-led.
  • Downstream cryptocurrency users — only as secondary victims of the laundering rails the operation depends on.

Observed Techniques

OAK v0.1's Tactic catalog is on-chain-extraction-focused; Cl0p's intrusion surface (off-chain mass-exploitation of MFT-product zero-days, custom web-shell deployment for data-exfiltration, and post-mid-2023 data-exfiltration-without-encryption operational style) sits outside that scope and is documented under external Group ID G0092 in the conventional cyber-threat-intel taxonomy. The on-chain Techniques observed in OAK-G14-attributable activity are concentrated on the payment-and-laundering side:

  • OAK-T7.001 (Mixer-Routed Hop) — observed as a partial / earlier-stage component of the broader Cl0p laundering chain, with usage of Bitcoin mixers declining sharply across 2022-to-2024 in step with the sector-wide post-Tornado-Cash-designation decline; per [chainalysis2025ransomware] mixer-share of ransomware-laundering volume fell substantially across 2023-to-2024 as a sector-wide effect and Cl0p followed the trend.
  • OAK-T7.002 (CEX Deposit-Address Layering) — the canonical post-2023 Cl0p off-ramp, with affiliate-controlled deposit-address activity at non-KYC, lax-KYC, and Russian-language commercial-criminal off-ramp venues a recurring industry-forensic signature; per Chainalysis and TRM Labs aggregate tracking, Cl0p downstream-laundering profile shows substantial overlap with the OAK-G03 Russian-language commercial-criminal off-ramp surface.
  • OAK-T7.003 (Cross-Asset / Cross-Chain Laundering) — observed in Cl0p laundering chains, with Bitcoin-to-stablecoin and Bitcoin-to-Monero conversion legs documented per industry-forensic write-ups.
  • OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by Mandiant, Microsoft, Chainalysis, TRM Labs, and Coveware to maintain Cl0p affiliate-cluster identification across encryptor-version rotations, across the mid-2023 data-extortion-only operating-model pivot, and across the post-2024 mass-exploitation-campaign-rotation surface (MOVEit → TeamCity → Cleo). The persistence of Bitcoin-funder-cluster identity across the cluster's 2019-to-2025 operating window — including across the multi-jurisdiction June 2021 Ukrainian-Cyber-Police-arrest disruption — is among the strongest indicators of operator continuity in the ransomware sector.
  • OAK-T8.002 (Cross-Chain Operator Continuity) — observed across mass-exploitation-campaign rotations and across the data-extortion-only operating-model pivot.
  • Adjacent / pre-incident vectors not in OAK v0.1 scope: off-chain initial access via mass-exploitation of MFT-product zero-days (Accellion FTA CVE-2021-27101 / CVE-2021-27102 / CVE-2021-27103 / CVE-2021-27104; GoAnywhere MFT CVE-2023-0669; MOVEit Transfer CVE-2023-34362; TeamCity CVE-2023-42793; Cleo CVE-2024-50623 / CVE-2024-55956), custom web-shell deployment (LEMURLOOT / "human2.aspx" web shell for the MOVEit campaign), and post-mid-2023 data-exfiltration-without-encryption operational style; these are the canonical Cl0p intrusion vectors and are documented in CISA AA23-158A, AA23-039A, and multi-vendor industry-forensic tracking.
  • Operating-model-novelty marker not in OAK v0.1 scope: the mid-2023 data-extortion-only pivot is an operating-model novelty in the ransomware-and-data-extortion ecosystem that does not map cleanly onto any on-chain Tactic and is not a credible candidate for OAK-T inclusion at v0.1. It is documented here as an operator-behaviour evolution because (a) it is the first publicly-documented case of a high-volume ransomware operator pivoting to a data-extortion-only operating model at scale, (b) successor and adjacent clusters have adopted variants of the data-extortion-only pattern (Karakurt, BianLian, RansomHouse), and (c) defender control-set design for ransomware-and-data-extortion response now needs to assume that encryption-deployment is not the only operating-model and data-disclosure-threat-only-extortion is part of the threat-actor toolkit.

Observed Examples

Worked examples in examples/:

The high-salience public-record events anchoring the cluster (narrative — see worked example above for the canonical entry):

  • Accellion FTA mass-exploitation campaign (December 2020-to-early-2021). Cl0p's first mass-exploitation-of-MFT-products campaign, exploiting the legacy Accellion File Transfer Appliance product across approximately 100 customer organisations using CVE-2021-27101 / CVE-2021-27102 / CVE-2021-27103 / CVE-2021-27104. Established the cluster's signature operational pattern. Attribution at confirmed per Mandiant FIN11 and CISA tracking.
  • GoAnywhere MFT mass-exploitation campaign (February 2023). Cl0p's second mass-exploitation-of-MFT-products campaign, exploiting Fortra's GoAnywhere MFT product across approximately 130 customer organisations using CVE-2023-0669; produced multiple high-profile victims including Community Health Systems and Procter & Gamble. Attribution at confirmed.
  • CISA / FBI AA23-039A "#StopRansomware: CLOP Ransomware" advisory (February 8, 2023). Joint CISA / FBI cyber-security advisory characterising Cl0p TTPs across the 2019-to-2023 operating window and the cluster's MFT-product mass-exploitation operational signature ([cisa2023aa23039aclop]). Attribution at confirmed.
  • MOVEit Transfer mass-exploitation campaign (May 27, 2023-to-present). Cl0p's canonical mass-exploitation-of-MFT-products campaign, exploiting Progress Software's MOVEit Transfer product across more than 2,500 named-victim organisations using CVE-2023-34362, with the LEMURLOOT custom web-shell deployed for data-exfiltration; produced downstream-affected-individual records exceeding 65 million and the largest single-campaign cyber-incident-disclosure-cohort in U.S. federal-government regulatory history. Sustained CISA / FBI / OFAC enforcement-and-advisory tempo through 2023-and-2024. Attribution at confirmed.
  • CISA / FBI AA23-158A "CL0P Ransomware Gang Exploits CVE-2023-34362 MOVEit Vulnerability" advisory (June 7, 2023). Joint CISA / FBI / NSA / U.S. Cyber Command cyber-security advisory characterising the MOVEit campaign and Cl0p TTPs ([cisa2023aa23158aclop]). Attribution at confirmed.
  • OFAC June 2023 designations of Cl0p-affiliated Russian nationals. OFAC SDN designations of multiple Cl0p-affiliated Russian nationals in June 2023, producing a cluster-attribution-and-named-individual-attribution layer beyond the prior AA23-039A and AA23-158A advisories ([ofac2023clopaffiliates]). Attribution at confirmed.
  • June 2021 Ukrainian Cyber Police arrests. Coordinated U.S. / South Korean / Ukrainian arrests of multiple Cl0p-affiliated individuals in Kyiv in June 2021, with seized infrastructure and extradition activity ([ukrcyberpolice2021clop]). Attribution at confirmed. The arrests degraded but did not extinguish the cluster; Cl0p-branded operations resumed within months.
  • Cl0p mid-2023 data-extortion-only operating-model pivot. From mid-2023 onward, Cl0p pivoted from the encryption-and-data-extortion double-extortion model to a data-extortion-only operating model in which encryption is no longer deployed and the negotiation surface is entirely the leaked-data-disclosure threat. Documented in industry-forensic tracking as an operating-model novelty marker. Attribution at confirmed (the pivot is observable in the public-record campaign data); the pivot's downstream effect on cluster economics and on adjacent-cluster behaviour is inferred-strong.
  • Cleo mass-exploitation campaign (late-2024). Cl0p-attributed mass-exploitation campaign exploiting Cleo's enterprise-software products using CVE-2024-50623 / CVE-2024-55956; extending the cluster's MFT-and-adjacent-enterprise-software mass-exploitation operational pattern beyond MOVEit. Attribution at inferred-strong per multiple industry-forensic write-ups.
  • Aggregate Cl0p metrics from CISA / FBI / OFAC reporting (>2,500 MOVEit-campaign victims; multi-year operational continuity from 2019-to-present; sustained leak-site operation) and from [chainalysis2025ransomware] and adjacent industry-forensic aggregate tracking (>$100M in confirmed extortion proceeds across the cluster's operating window; top-tier of ransomware-and-data-extortion volume per the 2023-and-2024 Chainalysis ransomware reports).
  • Worked examples for specific G14-mediated ransom-payment laundering flows are pending v0.x and will live under examples/ once the per-incident attribution surface stabilises sufficiently for the OAK confirmed / inferred-strong distinction; the MOVEit campaign is the highest-priority candidate.

Citations

  • [cisa2023aa23158aclop] — Joint CISA / FBI / NSA / U.S. Cyber Command cyber-security advisory AA23-158A on Cl0p MOVEit campaign, June 7, 2023.
  • [cisa2023aa23039aclop] — Joint CISA / FBI cyber-security advisory AA23-039A "#StopRansomware: CLOP Ransomware," February 8, 2023.
  • [ofac2023clopaffiliates] — U.S. Department of the Treasury OFAC June 2023 designations of multiple Cl0p-affiliated Russian nationals.
  • [ukrcyberpolice2021clop] — Ukrainian Cyber Police announcement of June 2021 arrests of multiple Cl0p-affiliated individuals in coordination with U.S. and South Korean law enforcement.
  • [mandiantfin11] — Mandiant FIN11 / TA505 / Cl0p tracker write-up on operator-cohort attribution.
  • [microsoftlacetempest] — Microsoft Threat Intelligence on Lace Tempest Cl0p-affiliated MOVEit-campaign-running sub-cluster.
  • [coveware2023moveit] — Coveware retrospective on the MOVEit campaign victim-cohort and ransom-payment aggregates.
  • [chainalysis2023clop] — Chainalysis forensic write-up of Cl0p downstream-laundering profile and MOVEit-campaign on-chain payment tracing.
  • [trmlabs2023moveit] — TRM Labs forensic write-up of MOVEit-campaign Bitcoin payment tracing.
  • [chainalysis2025ransomware] — Chainalysis 2024-recap ransomware report (referenced from G05 / G10 / G11 documentation as well); documents Cl0p aggregate proceeds and the data-extortion-only pivot.
  • [ofac2022tornado] — sector-wide mixer-laundering enforcement context (referenced for the post-2022 ransomware-mixer-share decline, not for shared cluster identity).

Discussion

On the attribution-strength split. The Cl0p operator-cluster attribution is confirmed at the OFAC-and-CISA-advisory layer — the June 2023 OFAC SDN designations of multiple Cl0p-affiliated Russian nationals, the June 2023 CISA / FBI / NSA / U.S. Cyber Command AA23-158A advisory on the MOVEit campaign, the February 2023 CISA / FBI AA23-039A advisory on Cl0p TTPs, and the June 2021 Ukrainian Cyber Police arrests of multiple Cl0p-affiliated individuals together produce a confirmed-grade public-attribution surface. Attribution that specific affiliate operators are tied to specific real-world identities beyond the OFAC-designated nationals is inferred-strong per Mandiant FIN11 / TA505 / Cl0p sub-cluster tracking. OAK contributors writing G14-attributed examples should preserve this attribution-strength split per-incident.

On why OAK-G14 is operating-brand cluster rather than TA505 operator-cohort. Naming this Group entry "TA505" would have framed the cluster at the broader operator-cohort level (TA505-attributed activity dates to 2014 and includes pre-Cl0p Dridex banking-malware distribution and FlawedAmmyy RAT campaigns), but would mis-frame the operating-model continuity model in the same way that the analogous framing would mis-frame OAK-G05 / G10 / G11. The Cl0p-branded ransomware-and-data-extortion operation is a sub-activity within the broader TA505 operator-cohort, and the Cl0p-branded operating-model continuity from 2019-to-present (across the MFT-mass-exploitation campaigns and across the mid-2023 data-extortion-only pivot) is the cleaner persistent identity than the broader TA505-cohort substrate. By the same logic, naming the Group at the individual-affiliate level would mis-frame the operating-brand-persistence pattern that defines the cluster.

On the cluster-boundary distinction with OAK-G05 / G10 / G11 (Russian-language operating-brand RaaS clusters). G05 (LockBit), G10 (ALPHV), G11 (Black Basta), and G14 (Cl0p) share Russian-language operator substrate and operate ransomware-and-data-extortion business models, but differ along the initial-access-vector axis (G14 is mass-exploitation-of-MFT-products-led; G05 / G10 / G11 are affiliate-distributed-broad-spectrum-intrusion-led), the operating-model axis (G14 pivoted to data-extortion-only from mid-2023 onward; G05 / G10 / G11 retain encryption-and-data-extortion double-extortion), the attribution-surface axis (G14 is confirmed-by-OFAC-SDN-designations-of-affiliates plus CISA-advisories; structurally adjacent to G05's confirmed-by-OFAC-and-DOJ surface and structurally distinct from G10's confirmed-by-disruption-and-indictment surface and G11's confirmed-by-CISA-advisory surface), and the exit-dynamic axis (G14 has not exited and remains operationally active as of v0.1; G05 was disrupted via Operation Cronos; G10 exited via operator-side scam; G11 internal-wound-down following internal-chats leak). Defenders running anti-G14 control sets should expect substantial overlap with anti-G05 / G10 / G11 control-set design at the off-chain-laundering-and-ransom-payment-flow layer (Russian-language commercial-criminal off-ramp profile) but should expect distinct on-chain attribution surfaces and distinct off-chain intrusion-vector control requirements (MFT-product defense as a Cl0p-specific high-priority control surface).

On the cluster-boundary distinction with OAK-G12 Scattered Spider. G14 (Cl0p) and G12 (Scattered Spider) are both ransomware-and-data-extortion-related clusters but differ along the operator-substrate axis (G14 is Russian-language operating-brand; G12 is English-speaking affiliate-collective), the initial-access-vector axis (G14 is mass-exploitation-of-MFT-products-led; G12 is social-engineering-and-help-desk-attack-led), and the operating-model axis (G14 runs its own ransomware-and-data-extortion infrastructure; G12 is an affiliate of multiple RaaS brands). The two clusters have not been documented as collaborating operationally on the public record and operate in distinct operator-substrate ecosystems.

On the data-extortion-only pivot as operating-model evolution. The mid-2023 Cl0p data-extortion-only pivot is an operating-model-novelty marker that defender control-set design needs to internalise even though it is not an OAK-T-classifiable on-chain Technique. The operating-model-surface in ransomware-and-data-extortion has expanded across 2023-to-2025 from encryption-and-data-extortion double-extortion to data-extortion-only operating models (Cl0p, Karakurt, BianLian, RansomHouse), to leaked-data-disclosure-with-press-pressure operating models, and to regulator-disclosure-regime weaponisation operating models (the OAK-G10 ALPHV SEC-filing tactic against MeridianLink, with Cl0p adopting variants of the regulator-disclosure pressure tactic). OAK should not absorb operating-model-novelty into its on-chain Tactic catalog at v0.1 — it would dilute the on-chain framing — but G14's documentation should preserve the marker for downstream consumers building incident-response runbooks. The defender takeaway is that ransomware-and-data-extortion negotiation in 2024-and-after operates under a substantively different operating-model and disclosure-regime threat model than it did in 2022, and counter-party-screening control sets need to assume that data-extortion-only and regulator-disclosure-pressure operating-models are part of the threat-actor toolkit.

On the relationship to OAK-G03 Russian laundering infrastructure. G03 (Russian laundering infrastructure, Garantex / Grinex / A7A5 lineage) was a documented downstream venue for some fraction of Cl0p proceeds, with the G14 / G03 chain showing substantial overlap per Chainalysis and TRM Labs aggregate tracking. The cluster's Russian-language commercial-criminal off-ramp profile shows distribution across multiple non-KYC and lax-KYC venues with concentration at OAK-G03-cluster venues during the 2022-to-2024 window. Defenders running OAK-G03 watchlists should expect substantial overlap with G14-attributed inflows.

On v0.x evolution. G14's 2026+ trajectory will depend on (a) whether further OFAC designations of Cl0p-affiliated individuals or infrastructure sustain the post-June-2023 enforcement tempo; (b) whether the cluster continues the mass-exploitation-of-MFT-and-adjacent-enterprise-software operational pattern (the late-2024 Cleo campaign suggests sustained operational durability through 2025); (c) whether the data-extortion-only operating-model pivot persists or whether the cluster reverts to encryption-and-data-extortion double-extortion; (d) whether a worked example of the MOVEit campaign is added under examples/ once the per-flow attribution surface stabilises sufficiently; and (e) whether successor or splinter activity (e.g., spin-off operating brands within the broader TA505 operator-cohort substrate) emerges. OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates. Future OAK Group additions in the ransomware-and-data-extortion sector — additional Conti-successor brands, RansomHub as a standalone successor-brand entry, dedicated data-extortion-only clusters (Karakurt, BianLian, RansomHouse) — would each warrant their own OAK-Gnn entry rather than extension of G05 / G10 / G11 / G14, on the same per-cluster identity principle.

Software used