OAK — OnChain Attack Knowledge

Threat actor · OAK-G15

OAK-G15 — RansomHub Ransomware-as-a-Service operation

Aliases
RansomHub (operating brand on Russian-language criminal forums and the cluster's Tor-hosted leak site, February 2024 → present, with the cluster's recruitment posts on RAMP and other Russian-language criminal-forum substrate explicitly positioning the brand as the post-ALPHV-exit-scam home for displaced affiliates), Greenbottle (some industry-forensic write-ups; minority usage), and the affiliate cohort identified across multiple industry-forensic write-ups as carrying ALPHV-cluster organisational continuity into the RansomHub operating brand following the early-March 2024 ALPHV exit-scam (notably "Notchy," the affiliate behind the Change Healthcare intrusion under OAK-G10, who publicly accused the ALPHV operator of stealing the affiliate share of the ~$22M Bitcoin payment and surfaced on RAMP and other Russian-language forums under reused persona signatures in the months following). For OAK-G15 purposes the cluster is the RansomHub RaaS operation — the core operator network behind the RansomHub encryptor (Go-language with cross-platform Windows / Linux / VMware ESXi builds), the affiliate-management infrastructure, and the leak-site operation — considered jointly with the ALPHV-and-LockBit-displaced affiliate stream that ran the highest-impact RansomHub intrusions of 2024. RansomHub is not a Conti-successor brand on the same lineage axis as OAK-G11 Black Basta, OAK-G16 Akira, OAK-G17 BlackByte, or OAK-G18 Karakurt — its organisational substrate is post-ALPHV-exit-scam absorber rather than post-ContiLeaks dispersal — and the cluster-boundary discipline matters for defender-side affiliate-cluster-reuse attribution work.
First observed in crypto
approximately February 2024 (RansomHub leak-site / RaaS-recruitment posts first observed on Russian-language criminal forums in February 2024, weeks before the early-March 2024 ALPHV operator-side exit-scam shutdown; the timing of RansomHub's launch positioned the cluster to absorb displaced ALPHV affiliates, and per multi-vendor industry-forensic tracking the post-March 2024 affiliate-onboarding tempo was unusually rapid for a new RaaS brand and is the canonical worked example of RaaS-affiliate-displacement-and-rapid-rebrand-absorption in the public record).
Attribution status
confirmed at the cluster-and-tooling level — joint CISA / FBI / HHS / MS-ISAC cyber-security advisory AA24-242A "StopRansomware: RansomHub Ransomware," August 29, 2024 ([cisa2024aa24242aransomhub]), characterising the cluster's TTPs across the healthcare and other critical-infrastructure sectors and naming RansomHub as the largest RaaS strain by victim-count in the immediate post-ALPHV-exit-scam window with more than 200 named victims through August 2024; sustained multi-vendor industry-forensic corroboration (Mandiant's UNC4393-adjacent and Notchy-affiliate tracking, Microsoft Threat Intelligence, Sophos, Symantec, Recorded Future, Coveware, Chainalysis, TRM Labs) characterising the Go-language encryptor lineage, the Russian-language operator-forum substrate, the affiliate-cut economics (~90 / 10 affiliate / operator split per industry-forensic tracking, more affiliate-favourable than the ALPHV ~85 / 15 baseline and substantially more affiliate-favourable than the LockBit ~80 / 20 baseline), and the post-ALPHV-affiliate-absorption pattern; Mandiant 2024 reporting describing RansomHub as "the largest 2024 RaaS by post-ALPHV-exit-scam affiliate-absorption volume" ([mandiant2024ransomhub]). RansomHub itself was not OFAC-designated as a cluster within its first 18 months of operation; that distinction makes G15 a confirmed-by-CISA-advisory-and-industry-forensic-corroboration rather than confirmed-by-OFAC-SDN-designation case at v0.1, structurally adjacent to OAK-G11 Black Basta on the attribution-strength axis. Attribution that specific ransom-payment flows trace to specific affiliate wallets within the RansomHub cluster is inferred-strong from industry forensic providers; the canonical instance is the cluster-continuity attestation linking Notchy and other ALPHV-displaced affiliates to RansomHub-cluster wallet activity in the months following the March 2024 ALPHV exit-scam ([chainalysis2025ransomware], [trm2024ransomhub]).
Active
yes as of v0.1 — RansomHub-branded extortion activity continued through 2024-and-2025 with sustained leak-site operation and continued ransom-payment flow tracked by industry-forensic providers. Per [chainalysis2025ransomware] the cluster's market-share among RaaS strains rose sharply across Q2-to-Q4 2024 in step with the post-ALPHV-exit-scam affiliate-displacement and the post-Operation-Cronos LockBit-volume-collapse, with RansomHub becoming the dominant single-strain RaaS brand by victim-count for substantial portions of 2024 (per Coveware and per CISA AA24-242A's victim-count metrics). The cluster is the canonical 2024 case in the public record of RaaS-brand-rotation absorbing displaced affiliates from prior-cluster terminations and warrants its own per-cluster identity treatment.

Description

OAK-G15 is the RansomHub ransomware-as-a-service operation: a Russian-language operator network that, between February 2024 and the present, has been the dominant single-strain RaaS brand by victim-count for substantial portions of 2024 and is the canonical post-ALPHV-exit-scam-affiliate-absorber cluster in the public record. The cluster is genuinely distinct from prior OAK Groups: from OAK-G05 LockBit, OAK-G10 ALPHV / BlackCat, OAK-G11 Black Basta, and OAK-G14 Cl0p along the organisational-substrate axis — RansomHub is a post-ALPHV-exit-scam absorber rather than a Conti-successor brand or an independently-founded operating brand — and along the affiliate-cut-economics axis (RansomHub's reported ~90 / 10 affiliate / operator split is the most affiliate-favourable in the major-RaaS-strain public record, deliberately calibrated to attract displaced ALPHV affiliates in the immediate post-exit-scam window); from OAK-G12 Scattered Spider along the operating-brand-vs-affiliate-collective axis (G15 is a Russian-language operating-brand cluster; Scattered Spider is an English-speaking affiliate-collective that has run intrusions against RansomHub among other RaaS brands in 2024-and-2025); and from OAK-G16 Akira, OAK-G17 BlackByte, and OAK-G18 Karakurt along the Conti-lineage axis (G15 is not a Conti-successor brand, while G16, G17, and G18 each carry distinct Conti-organisational-continuity attestations). RansomHub's inclusion in OAK is not because it is a crypto-native operator — its targets are overwhelmingly traditional-enterprise IT estates, with healthcare, government, and financial-services sectors over-represented in the public victim record — but because cryptocurrency is the load-bearing payment-and-laundering rail of the entire RaaS business model, because the cluster's post-ALPHV-exit-scam absorption pattern is the canonical worked example in the public record of RaaS-brand-rotation absorbing displaced affiliates from prior-cluster terminations, and because the August 2024 CISA AA24-242A advisory established the cluster as a confirmed-grade RaaS attribution warranting per-cluster identity treatment alongside G05 / G10 / G11 / G14.

The operational model is a textbook ransomware-as-a-service split with several cluster-distinctive features. RansomHub's encryptor lineage is Go-language with cross-platform Windows / Linux / VMware ESXi builds — a tooling choice that follows the broader 2022–2024 ransomware-sector migration toward memory-safe and cross-compilable systems languages (Rust for ALPHV, Go for RansomHub, with C++ for LockBit's principal lineage and Rust-and-C++ for Black Basta) and produces cross-platform encryptor builds from a shared codebase that complicates reverse-engineering and detection work for incident-response vendors. Affiliates received approximately 90% of the ransom-payment cut per industry-forensic tracking (notably more affiliate-favourable than the LockBit ~80% / operator ~20% baseline and the ALPHV ~85% / 15% baseline), with payments routed to affiliate-controlled wallets under the operator's payment-and-negotiation-portal supervision. The operator persona ran the RansomHub leak site, the affiliate panel, the negotiation-chat infrastructure, and the Russian-language-forum recruitment posture; the affiliate cohort was unusually heterogeneous and included substantial overlap with the ALPHV-displaced affiliate stream (Notchy and other ALPHV affiliates re-surfacing on RAMP and other Russian-language criminal forums under reused persona identifiers and known-cluster wallet-funder signatures), with the Scattered Spider / UNC3944 affiliate-collective also documented as running intrusions under the RansomHub brand from 2024 onward (per multiple DOJ unsealings and Mandiant tracking; Scattered Spider's 2024-and-2025 RaaS-brand rotation through ALPHV → RansomHub → DragonForce / Qilin is itself a defender-relevant operator-behaviour evolution, treated under OAK-G12).

The cluster's defender-relevant signature is upstream-extraction-cluster with confirmed-grade public attribution at the CISA-advisory layer (rather than the OFAC-SDN layer), with rapid-affiliate-absorption-from-prior-cluster-terminations as the operational-continuity attestation. The August 2024 CISA AA24-242A advisory specifically called out the post-ALPHV affiliate-displacement dynamic and the cluster's resulting victim-count growth, and named multiple high-salience victims including Change Healthcare data-leak follow-on (RansomHub-attributed re-extortion of the Change-Healthcare-affiliate-held data following the ALPHV operator-side exit-scam, in April 2024 — a structurally novel post-exit-scam-affiliate-data-monetisation operating pattern), Christie's auction house (May 2024), and Frontier Communications (April 2024). Defenders running G15-tuned controls should expect (a) substantial overlap with anti-G10 ALPHV control-set design at the off-chain intrusion layer and at the on-chain laundering-and-ransom-payment-flow layer (Russian-language commercial-criminal off-ramp profile), (b) cluster-distinctive affiliate-cluster-reuse signal across the ALPHV → RansomHub transition (per OAK-T8.001 attribution-side methodology), and (c) the post-exit-scam-affiliate-data-monetisation pattern as a sustained behaviour rather than one-off (the Change Healthcare re-extortion is the canonical case but the pattern generalises to any prior-cluster-termination event where affiliates retain residual access to victim-data archives).

Targeting profile

OAK-G15's victim profile is enterprise-IT rather than crypto-native, with sector concentration in U.S. healthcare, government / public sector, financial services, retail and consumer-services, and manufacturing — broadly consistent with the inherited ALPHV-affiliate-cohort targeting profile:

  • U.S. healthcare-sector firms — Change Healthcare data-leak re-extortion (April 2024, the canonical post-exit-scam-affiliate-data-monetisation case; structurally novel as a re-extortion event downstream of OAK-G10's terminal-phase exit-scam), multiple regional hospital systems and clinical networks; healthcare over-representation in the RansomHub record was a stated reason for the AA24-242A joint-advisory issuance and for HHS-sectoral-response tempo.
  • Government and public-sector organisations — multiple U.S. state and municipal governments, education-sector targets, and non-U.S. government bodies; targeting profile broadly consistent with cross-sector RaaS-cohort behaviour and inherited from displaced ALPHV affiliates.
  • Financial-sector and consumer-services firms — Christie's auction house (May 2024, with the breach disrupting the firm's spring auction season and producing a high-profile press cycle), Frontier Communications (April 2024, with multi-million-customer impact), multiple regional banks and credit unions; consumer-services targeting reflects the Scattered-Spider-aligned affiliate stream's continued operational tempo under the RansomHub brand.
  • Retail and manufacturing firms — sustained intrusion tempo across multiple sectors per AA24-242A; broadly consistent with the cross-sector targeting profile inherited from the ALPHV-affiliate-cohort substrate.
  • Critical-infrastructure operators — water utilities, energy-sector firms, and U.S. critical-infrastructure-sector targets per AA24-242A; the cross-sector targeting profile was a stated escalation factor in the August 2024 advisory tempo.
  • Cryptocurrency-industry firms as occasional targets — present but not the dominant target class; G15 is enterprise-extortion-led, not crypto-native-extraction-led.
  • Downstream cryptocurrency users — only as secondary victims of the laundering rails the operation depends on (the load on the Russian-language commercial-criminal off-ramp surface from G15 flows is part of the volume that produced sustained 2024-and-2025 OAK-G03 enforcement tempo).

Observed Techniques

OAK v0.1's Tactic catalog is on-chain-extraction-focused; RansomHub's intrusion surface (off-chain enterprise IT compromise, including Scattered-Spider-distinctive help-desk voice-phishing and exploitation-of-public-facing-vulnerabilities for affiliates inherited from ALPHV) sits outside that scope and is documented in CISA AA24-242A and the conventional cyber-threat-intel taxonomy. The on-chain Techniques observed in OAK-G15-attributable activity are concentrated on the payment-and-laundering side:

  • OAK-T7.001 (Mixer-Routed Hop) — observed as a partial / earlier-stage component of the broader RansomHub laundering chain, with usage of Bitcoin mixers continuing the sector-wide post-Tornado-Cash-designation decline ([ofac2022tornado]); per [chainalysis2025ransomware] mixer-share of ransomware-laundering volume continued falling across 2024 and RansomHub followed the trend.
  • OAK-T7.002 (CEX Deposit-Address Layering) — the canonical RansomHub off-ramp for the Bitcoin portion of ransom payments, with affiliate-controlled deposit-address activity at non-KYC and lax-KYC venues a recurring industry-forensic signature; the cluster's downstream-laundering profile shows substantial overlap with the inherited ALPHV-affiliate-cohort layering pattern per [trm2024ransomhub].
  • OAK-T7.003 (Cross-Asset / Cross-Chain Laundering) — observed in RansomHub laundering chains, with Bitcoin-to-stablecoin and Bitcoin-to-Monero conversion legs documented per industry-forensic write-ups; the cross-asset / cross-chain layering profile is broadly consistent with the inherited ALPHV-affiliate-cohort pattern.
  • OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by Mandiant, Microsoft, Chainalysis, TRM Labs, and Recorded Future to maintain RansomHub affiliate-cluster identification across the ALPHV → RansomHub affiliate-displacement transition. The persistence of Bitcoin-funder-cluster identity from ALPHV-affiliate wallets to RansomHub-affiliate wallets across the March-to-Q2 2024 displacement window is the canonical 2024 worked case for T8.001 against a RaaS-affiliate-rotation event; the methodology generalises to other RaaS-brand-rotation dynamics.
  • OAK-T8.002 (Cross-Chain Operator Continuity) — observed in the affiliate-displacement pattern after March 2024, with multiple ALPHV affiliates (notably Notchy) re-surfacing on RAMP and other Russian-language criminal forums under reused persona identifiers and known-cluster wallet-funder signatures across the RansomHub onboarding window; per [chainalysis2025ransomware] the cluster-continuity signal across the ALPHV-to-RansomHub transition is inferred-strong and is the basis for OAK-G15's confirmed-cluster-attribution-with-inferred-strong-affiliate-cluster-continuity treatment.
  • Adjacent / pre-incident vectors not in OAK v0.1 scope: off-chain initial access via Scattered-Spider-style help-desk voice-phishing, exploitation-of-public-facing-vulnerabilities (Citrix Bleed, Fortinet, Microsoft Exchange ProxyShell-class), and Active-Directory-trust-relationship abuse for ESXi-host targeting; these are the canonical RansomHub-affiliate intrusion vectors and overlap substantially with the inherited ALPHV-affiliate-cohort intrusion-vector profile.
  • Operating-pattern novelty not in OAK v0.1 scope: the April 2024 Change Healthcare data-leak re-extortion is a tactical novelty in the operator-pressure-tactic category — RansomHub-affiliate Notchy retained access to the Change Healthcare data archive after the ALPHV operator-side exit-scam diverted the original ~$22M Bitcoin ransom payment, and re-monetised the data archive under the RansomHub brand by threatening data-disclosure unless a second ransom was paid. This is the first publicly-documented case of post-exit-scam-affiliate-data-monetisation as an operating-pattern evolution, and successor RaaS brands have not yet replicated the pattern at scale, but defender control-set design for ransomware response now needs to assume that the affiliate-vs-operator split of victim-data archives may persist beyond the prior-cluster-termination event and that re-extortion under successor-brand attribution is part of the threat-actor toolkit.

Observed Examples

Worked examples in examples/:

  • examples/2024-02-change-healthcare-ransom.md — original ALPHV / Notchy intrusion of Optum / UnitedHealth Change Healthcare clearinghouse; cited from G15 because RansomHub absorbed the dispersed ALPHV affiliates after the March 2024 exit-scam.
  • examples/2024-04-change-healthcare-reextortion.md — RansomHub-attributed re-extortion against the same victim using exfiltrated data from the original ALPHV intrusion; canonical G15 worked example, anchoring the post-exit-scam affiliate-dispersal pattern.

The high-salience public-record events anchoring the cluster (narrative — see worked examples above for the canonical entries):

  • CISA / FBI / HHS / MS-ISAC AA24-242A joint advisory (August 29, 2024). "StopRansomware: RansomHub Ransomware" — characterising the cluster's TTPs across the healthcare and other critical-infrastructure sectors, naming RansomHub as the dominant 2024 RaaS strain by victim-count with more than 200 named victims through August 2024, and identifying the cluster's post-ALPHV-affiliate-absorption operational substrate ([cisa2024aa24242aransomhub]). Attribution at confirmed at the cluster level.
  • Change Healthcare data-leak re-extortion (April 2024). RansomHub-affiliate Notchy (the original ALPHV affiliate behind the February 2024 Change Healthcare intrusion under OAK-G10) re-monetised the Change Healthcare data archive under the RansomHub brand by threatening data-disclosure unless a second ransom was paid; the first publicly-documented case of post-exit-scam-affiliate-data-monetisation in the ransomware-and-data-extortion ecosystem. Documented per industry-forensic tracking and per HHS-sectoral response ([chainalysis2025ransomware], [trm2024ransomhub]). Attribution at confirmed at the cluster level; attribution of the Notchy-as-RansomHub-affiliate continuity is inferred-strong.
  • Christie's auction house intrusion (May 2024). RansomHub-attributed encryption-and-data-extortion event against Christie's, disrupting the firm's spring auction season; high-profile press cycle and stated escalation factor for the AA24-242A advisory tempo ([reuters2024christies]). Attribution at confirmed at the cluster level.
  • Frontier Communications intrusion (April 2024). RansomHub-attributed encryption-and-data-extortion event against Frontier Communications with multi-million-customer-record exposure; named in AA24-242A as a high-impact victim-cohort case ([reuters2024frontier]). Attribution at confirmed at the cluster level.
  • Aggregate RansomHub metrics from [cisa2024aa24242aransomhub] (>200 named victims through August 2024 across 12 of 16 critical-infrastructure sectors; cross-sector targeting profile inherited from displaced ALPHV affiliates) and from [chainalysis2025ransomware] (cluster-share of total ransomware payments rising sharply across Q2-to-Q4 2024 in step with the post-ALPHV-exit-scam affiliate-displacement and the post-Operation-Cronos LockBit-volume-collapse).
  • Worked examples for specific G15-mediated ransom-payment laundering flows are pending v0.x and will live under examples/ once the per-incident attribution surface stabilises sufficiently for the OAK confirmed / inferred-strong distinction; the Change Healthcare re-extortion case is the highest-priority candidate.

Citations

  • [cisa2024aa24242aransomhub] — CISA / FBI / HHS / MS-ISAC joint cyber-security advisory AA24-242A, "StopRansomware: RansomHub Ransomware," August 29, 2024.
  • [mandiant2024ransomhub] — Mandiant 2024 reporting on RansomHub as the largest 2024 RaaS strain by post-ALPHV-exit-scam affiliate-absorption volume.
  • [chainalysis2025ransomware] — Chainalysis 2024-recap ransomware report (referenced from G05 / G10 / G11 / G14 documentation as well); documents RansomHub cluster-share trajectory and the post-ALPHV-affiliate-displacement absorption pattern.
  • [trm2024ransomhub] — TRM Labs forensic write-up of RansomHub on-chain payment tracing and the ALPHV-to-RansomHub affiliate-cluster-reuse continuity.
  • [chainalysis2024alphvexit] — Chainalysis forensic write-up of the ALPHV / BlackCat exit-scam (referenced from G10); foundational organisational-continuity context for the ALPHV-to-RansomHub affiliate-displacement pattern.
  • [reuters2024christies] — Reuters reporting on the May 2024 RansomHub-attributed Christie's intrusion.
  • [reuters2024frontier] — Reuters reporting on the April 2024 RansomHub-attributed Frontier Communications intrusion.
  • [ofac2022tornado] — sector-wide mixer-laundering enforcement context (referenced for the post-2022 ransomware-mixer-share decline, not for shared cluster identity).

Discussion

On the attribution-strength split. The RansomHub operator-cluster attribution is confirmed at the CISA-advisory layer — the August 2024 AA24-242A joint advisory by CISA, FBI, HHS, and MS-ISAC is the canonical national-government-coordinated public attribution document for the cluster — but is not OFAC-SDN-confirmed or DOJ-indictment-confirmed at the principal-operator level as of v0.1. This makes G15 a confirmed-by-CISA-advisory rather than confirmed-by-OFAC-SDN-designation case, structurally adjacent to OAK-G11 Black Basta on the attribution-strength axis and structurally distinct from OAK-G05 LockBit (confirmed-by-OFAC-SDN-designation-and-DOJ-indictment) and OAK-G10 ALPHV (confirmed-by-disruption-and-indictment). OAK contributors writing G15-attributed examples should preserve this attribution-strength split per-incident, and should not infer OFAC-style asset-freeze-readiness from the underlying confirmed-grade cluster attribution. Attribution that specific affiliate operators are tied to specific real-world identities is inferred-strong per Mandiant and TRM Labs sub-cluster tracking; no DOJ unsealings of RansomHub-principal-operator indictments have been issued as of v0.1.

On why OAK-G15 is RaaS-operation rather than individual-affiliate and not encryptor-strain. Naming this Group entry "RansomHub encryptor" or framing it at the individual-affiliate level (Notchy, the Scattered Spider members named in DOJ indictments who have rotated through RansomHub) would mis-frame the operational continuity model in the same way the analogous framing would mis-frame OAK-G05 / G10 / G11 / G14. The operator-and-affiliate-cluster is a cleaner persistent identity than the strain or the individual affiliate; OAK-G15 sits at the same level of abstraction as OAK-G05, G10, G11, and G14.

On the cluster-boundary distinction with OAK-G10 ALPHV. G15 (RansomHub) and G10 (ALPHV / BlackCat) are the canonical prior-cluster-termination → successor-brand-absorption pair on the OAK roster. They share Russian-language operator substrate, share substantial affiliate-cohort overlap (Notchy and other ALPHV-displaced affiliates re-surfacing under RansomHub), and share inherited intrusion-vector and laundering-pattern profiles. They differ along the operating-window axis (G10 ran February 2024 → early-March 2024 exit-scam; G15 launched February 2024 and continues through v0.1), the operator-cohort axis (the RansomHub operator persona is distinct from the ALPHV operator persona; the displaced ALPHV operator did not migrate to RansomHub leadership but absconded with the exit-scam proceeds), and the exit-dynamic axis (G10 closed via operator-side scam; G15 remains operationally active). Defenders running anti-G15 watchlist surfaces should treat the cluster as inheriting the G10 affiliate-cluster signal but differing from the G10 operator-cluster signal — and the cluster-continuity attestation is at the affiliate-cluster level rather than at the operator-cluster level.

On the cluster-boundary distinction with OAK-G16 / G17 / G18 (Conti-successor brands). G15 is not a Conti-successor brand. G16 (Akira), G17 (BlackByte), and G18 (Karakurt) each carry distinct Conti-organisational-continuity attestations from the February-to-May 2022 ContiLeaks dispersal window; G15's organisational substrate is the post-ALPHV-exit-scam absorber dynamic of early-2024, structurally distinct from the post-ContiLeaks dispersal pattern. Defenders running affiliate-cluster-reuse attribution work across the ransomware sector should preserve this distinction explicitly, since conflating the two organisational-continuity patterns would dilute the per-cluster identity discipline that motivates OAK's per-Group-page treatment.

On the relationship to OAK-G03 Russian laundering infrastructure. G03 (Russian laundering infrastructure, Garantex / Grinex / A7A5 lineage) was a documented downstream venue for some fraction of RansomHub proceeds, with the G15 / G03 chain showing distribution across multiple non-KYC and lax-KYC venues consistent with the inherited ALPHV-affiliate-cohort profile per industry-forensic tracking. Defenders running OAK-G03 watchlists should expect some overlap with G15-attributed inflows, broadly consistent with the level of overlap expected with G10-attributed inflows.

On v0.x evolution. G15's 2026+ trajectory will depend on (a) whether further OFAC designations or DOJ indictments of RansomHub-principal-operators emerge, (b) whether successor-brand affiliate-displacement-and-absorption dynamics produce additional RaaS-brand-rotation events for the Scattered-Spider-aligned affiliate stream and other cross-cluster-mobile affiliate cohorts, (c) whether the post-exit-scam-affiliate-data-monetisation operating-pattern novelty produces additional public-record instances at successor-brand scale, and (d) whether a worked example of the Change Healthcare re-extortion case is added under examples/ once the per-flow attribution surface stabilises sufficiently. OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates.

Software used