OAK — OnChain Attack Knowledge

Threat actor · OAK-G16

OAK-G16 — Akira Ransomware-as-a-Service operation

Aliases
Akira (operating brand on Russian-language criminal forums and the cluster's Tor-hosted leak site, March 2023 → present, with a self-styled retro-1980s-terminal leak-site aesthetic that has been used as a low-fidelity operator-self-identification signal in industry-forensic tracking), GOLD SAHARA (Secureworks Counter Threat Unit tracker name), Storm-1567 (Microsoft tracker name for the Akira-affiliated principal sub-cluster), Punk Spider (some industry-forensic write-ups; minority usage), and the affiliate cohort identified across multiple industry-forensic write-ups as carrying Conti-codebase-related lineage from the February-to-May 2022 ContiLeaks dispersal into the Akira operating brand. The Akira-as-Conti-successor lineage is separate from but parallel to OAK-G11 Black Basta — both clusters carry distinct Conti-codebase-related lineage attestations but were launched by different sub-cohorts within the broader post-ContiLeaks operator dispersal, and the operator-cohort tracking across Mandiant, Microsoft, and Sophos write-ups treats Akira and Black Basta as separate Conti-successor brands with distinct affiliate cohorts and distinct encryptor-codebase development trajectories. For OAK-G16 purposes the cluster is the Akira RaaS operation — the core operator network behind the Akira encryptor (C++-and-Rust lineage with cross-platform Windows / Linux / VMware ESXi variants, with the Megazord encryptor-variant introduced in late-2023 as a Rust-based redevelopment), the affiliate-management infrastructure, and the leak-site operation — considered jointly with the Conti-codebase-related affiliate cohort that ran the cluster's first 18 months of intrusions.
First observed in crypto
approximately March 2023 (Akira leak-site / RaaS-recruitment posts first observed on Russian-language criminal forums in March 2023, with cluster-attributed intrusions documented from late-March 2023 onward; the RaaS model with Bitcoin-denominated ransom payments has been the operational default since inception).
Attribution status
confirmed at the cluster-and-tooling level — joint CISA / FBI / Europol EC3 / Netherlands NCSC-NL cyber-security advisory AA24-109A "StopRansomware: Akira Ransomware," April 18, 2024 ([cisa2024aa24109aakira]), characterising the cluster's TTPs across the manufacturing, education, financial-services, and other sectors, naming Akira as a high-volume RaaS strain with approximately 250 victim organisations and approximately $42M in confirmed ransom-payment proceeds through January 2024, and identifying the Akira-affiliate cohort's exploitation-of-public-facing-vulnerabilities and Cisco-VPN-without-MFA initial-access vectors; sustained multi-vendor industry-forensic corroboration (Mandiant tracking, Microsoft Storm-1567, Sophos X-Ops, Recorded Future, Coveware, Chainalysis, TRM Labs) characterising the C++-and-Rust encryptor lineage, the Russian-language operator-forum substrate, the Conti-codebase-related lineage attestation, and the affiliate-cut economics; Sophos late-2023 reporting on the Megazord encryptor-variant as a Rust-based redevelopment of the Akira codebase ([sophos2023akira]). The Conti-codebase-related lineage claim is inferred-strong — overlap of operator personas, encryptor-architecture decisions, and TTP-fingerprint signal across the Conti-shutdown / Akira-launch window are documented across Mandiant, Microsoft, and Sophos tracking but the cluster has not been individually OFAC-designated or DOJ-indicted at the principal-operator level as of v0.1. Attribution that specific ransom-payment flows trace to specific affiliate wallets within the Akira cluster is inferred-strong from industry forensic providers; per CISA AA24-109A and Chainalysis aggregate tracking, Akira-attributable ransom-payment proceeds across the cluster's first 10 months of operation total approximately $42M, with downstream laundering routes sharing the broader Russian-language commercial-criminal off-ramp profile.
Active
yes as of v0.1 — Akira-branded extortion activity continued through 2024-and-2025 with sustained leak-site operation, continued ransom-payment flow tracked by industry-forensic providers, and continued cross-platform encryptor-variant development (Megazord Rust-based variant from late-2023 onward, with continued ESXi-and-Linux-targeting development). Per [chainalysis2025ransomware] the cluster's market-share among RaaS strains has been sustained across 2024-and-2025 in step with the post-Operation-Cronos LockBit-volume-collapse, the post-ALPHV-exit-scam affiliate-displacement, and the post-Black-Basta-internal-wind-down dispersal, with Akira positioned as one of the durable mid-volume RaaS strains across the 2023-to-2025 window.

Description

OAK-G16 is the Akira ransomware-as-a-service operation: a Russian-language operator network that, between March 2023 and the present, has been one of the durable mid-volume RaaS strains in the post-Conti-dispersal window alongside OAK-G11 Black Basta and adjacent Conti-successor brands. The cluster is genuinely distinct from prior OAK Groups along multiple axes: from OAK-G05 LockBit, OAK-G10 ALPHV / BlackCat, and OAK-G14 Cl0p along the organisational-substrate axis (Akira is a Conti-codebase-related cluster from the post-ContiLeaks dispersal; LockBit, ALPHV, and Cl0p are independently-founded operating brands that pre-date or operate outside the Conti dispersal substrate); from OAK-G11 Black Basta along the Conti-successor sub-cohort axis (Akira and Black Basta are separate Conti-successor brands with distinct affiliate cohorts, distinct encryptor-codebase development trajectories, and distinct operating-pattern profiles, and OAK contributors writing G16-attributed content should preserve the cluster-boundary distinction with G11 explicitly to avoid over-aggregating Conti-successor activity into a single cluster); from OAK-G15 RansomHub along the organisational-substrate axis (G16 is post-ContiLeaks-dispersal; G15 is post-ALPHV-exit-scam absorber); from OAK-G17 BlackByte and OAK-G18 Karakurt along the Conti-successor sub-cohort axis (G16, G17, and G18 each carry distinct Conti-codebase-related lineage attestations from different sub-cohorts within the post-ContiLeaks dispersal); and from OAK-G12 Scattered Spider along the operating-brand-vs-affiliate-collective axis. Akira's inclusion in OAK is not because it is a crypto-native operator — its targets are overwhelmingly traditional-enterprise IT estates, with manufacturing, education, financial-services, and small-and-medium-business firms over-represented in the public victim record — but because cryptocurrency is the load-bearing payment-and-laundering rail of the entire RaaS business model and because the April 2024 CISA AA24-109A advisory established the cluster as a confirmed-grade RaaS attribution warranting per-cluster identity treatment alongside G05 / G10 / G11 / G14 / G15.

The operational model is a Conti-codebase-related ransomware-as-a-service split with several cluster-distinctive features. Akira's encryptor lineage is C++-and-Rust with cross-platform Windows / Linux / VMware ESXi builds; the cluster was an early adopter of the Rust-based redevelopment trajectory in mid-2023 with the Megazord variant (per Sophos late-2023 tracking), continuing the broader 2022-to-2024 ransomware-sector migration toward memory-safe systems languages. The cluster's Conti-codebase-related lineage is documented per multi-vendor tracking — overlap of operator personas across the post-ContiLeaks dispersal window, encryptor-architecture decisions consistent with Conti-codebase-related origins, and TTP-fingerprint signal (Cobalt Strike post-exploit, Empire / BloodHound lateral-movement, ESXi-host-targeted encryption) consistent with broader Conti-successor-cohort behaviour. Akira's signature initial-access vector through 2023-and-2024 was exploitation-of-Cisco-VPN-appliances-without-MFA: per CISA AA24-109A, Akira affiliates exploited Cisco ASA / FTD VPN appliances lacking multi-factor authentication as a recurring initial-access vector, with credential-spraying-and-brute-forcing of single-factor VPN accounts producing affiliate footholds across multi-sector victim cohorts. Affiliate-cut economics are reported in the mid-range of the major RaaS strains (industry-forensic estimates place Akira's affiliate split between LockBit's ~80% and ALPHV's ~85% baselines), with payments routed to affiliate-controlled wallets under the operator's payment-and-negotiation-portal supervision. The cluster's affiliate cohort is documented as overlapping with the broader Russian-language commercial-criminal substrate; multiple affiliate-cluster-reuse signals across Akira and adjacent Conti-successor brands have been documented per industry-forensic tracking, broadly consistent with the cross-cluster-mobile affiliate dynamic that defines the post-ContiLeaks dispersal window.

The cluster's defender-relevant signature is upstream-extraction-cluster with confirmed-grade public attribution at the CISA-advisory layer (rather than the OFAC-SDN layer), Conti-codebase-related lineage from the post-ContiLeaks dispersal, and signature exploitation-of-Cisco-VPN-without-MFA initial-access vector through 2023-and-2024. Per CISA AA24-109A the cluster had reached approximately 250 named-victim organisations and approximately $42M in confirmed ransom-payment proceeds through January 2024, with sustained victim-cohort growth across 2024-and-2025. Defenders running G16-tuned controls should expect (a) substantial overlap with anti-G11 Black Basta control-set design at the off-chain intrusion layer (loader chains, post-exploit tooling, lateral-movement, ESXi-host-targeting) and at the on-chain laundering-and-ransom-payment-flow layer (Russian-language commercial-criminal off-ramp profile), (b) cluster-distinctive Cisco-VPN-without-MFA initial-access-vector defense as an Akira-specific high-priority control surface, and (c) Conti-codebase-related operator-cluster-reuse signal across multiple successor brands per OAK-T8.001 attribution-side methodology.

Targeting profile

OAK-G16's victim profile is enterprise-IT rather than crypto-native, with sector concentration in manufacturing, education, financial services, professional services, healthcare, and small-and-medium-business — broadly consistent with broad-spectrum Conti-successor-cohort targeting:

  • Manufacturing and industrial-sector firms — multiple regional manufacturers and industrial-supply-chain firms; manufacturing over-representation in the Akira record reflects the cluster's exploitation-of-Cisco-VPN-without-MFA initial-access vector against mid-market manufacturing-sector enterprise IT.
  • Education-sector institutions — multiple U.S. and European universities, K-12 school districts, and education-adjacent organisations; education over-representation in the Akira record was a stated targeting-profile factor in CISA AA24-109A.
  • Financial-services firms — multiple regional banks, credit unions, insurance firms, and financial-services-adjacent organisations; financial-sector targeting was less concentrated than in the G05 LockBit profile but consistent with broad-spectrum RaaS targeting.
  • Professional-services and legal-sector firms — multiple law firms, accounting firms, and consulting firms; professional-services targeting reflects the cluster's mid-market-enterprise-IT focus.
  • Healthcare-sector firms — multiple regional hospital systems, clinical networks, and healthcare-adjacent organisations; healthcare targeting was less concentrated than in the G10 ALPHV or G11 Black Basta profiles but consistent with cross-sector RaaS-cohort behaviour.
  • Critical-infrastructure operators — present per CISA AA24-109A; sustained cross-sector targeting across 12 of 16 critical-infrastructure sectors.
  • Cryptocurrency-industry firms as occasional targets — present but not the dominant target class; G16 is enterprise-extortion-led, not crypto-native-extraction-led.
  • Downstream cryptocurrency users — only as secondary victims of the laundering rails the operation depends on.

Observed Techniques

OAK v0.1's Tactic catalog is on-chain-extraction-focused; Akira's intrusion surface (off-chain enterprise IT compromise via Cisco-VPN-without-MFA exploitation, Cobalt Strike post-exploit, Empire / BloodHound lateral-movement, ESXi-host-targeted encryption) sits outside that scope and is documented in CISA AA24-109A and the conventional cyber-threat-intel taxonomy. The on-chain Techniques observed in OAK-G16-attributable activity are concentrated on the payment-and-laundering side:

  • OAK-T7.001 (Mixer-Routed Hop) — observed as a partial / earlier-stage component of the broader Akira laundering chain, with usage of Bitcoin mixers continuing the sector-wide post-Tornado-Cash-designation decline ([ofac2022tornado]); per [chainalysis2025ransomware] mixer-share of ransomware-laundering volume continued falling across 2023-and-2024 and Akira followed the trend.
  • OAK-T7.002 (CEX Deposit-Address Layering) — the canonical Akira off-ramp for the Bitcoin portion of ransom payments, with affiliate-controlled deposit-address activity at non-KYC and lax-KYC venues a recurring industry-forensic signature; the cluster's downstream-laundering profile shows substantial overlap with the broader Russian-language commercial-criminal off-ramp surface.
  • OAK-T7.003 (Cross-Asset / Cross-Chain Laundering) — observed in Akira laundering chains, with Bitcoin-to-stablecoin and Bitcoin-to-Monero conversion legs documented per industry-forensic write-ups.
  • OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by Mandiant, Microsoft, Sophos, Chainalysis, and TRM Labs to maintain Akira affiliate-cluster identification across encryptor-version rotations (C++ → Megazord-Rust), across the Conti-shutdown / Akira-launch organisational-continuity window, and across cross-cluster-mobile affiliate movement to and from adjacent Conti-successor brands. The persistence of Bitcoin-funder-cluster identity across the Conti-to-Akira dispersal window is among the strongest indicators of operator continuity in the ransomware sector for the post-2022-cohort.
  • OAK-T8.002 (Cross-Chain Operator Continuity) — observed in cross-cluster-mobile affiliate movement across Akira and adjacent Conti-successor brands per industry-forensic tracking.
  • Adjacent / pre-incident vectors not in OAK v0.1 scope: off-chain initial access via exploitation of Cisco ASA / FTD VPN appliances lacking MFA (the cluster's signature 2023-and-2024 vector, per CISA AA24-109A), credential-spraying-and-brute-forcing, exploitation of public-facing vulnerabilities (Cisco AnyConnect, Veeam Backup, ESXi-host vulnerabilities), and Active-Directory-trust-relationship abuse for ESXi-host targeting; these are the canonical Akira-affiliate intrusion vectors and overlap substantially with the broader Conti-successor-cohort intrusion-vector profile while preserving the cluster-distinctive Cisco-VPN-without-MFA marker.

Observed Examples

No public incidents at v0.1 — worked examples pending per-incident forensic publication.

OAK v0.1 does not yet contain a worked example whose primary axis is an Akira target; the on-chain angle of G16 is the laundering of ransom payments rather than direct crypto-firm intrusion, and the cluster's most defender-relevant payment-tracing case is on the watch-list for v0.x worked-example coverage. The high-salience public-record events anchoring the cluster:

  • CISA / FBI / Europol EC3 / NCSC-NL AA24-109A joint advisory (April 18, 2024). "StopRansomware: Akira Ransomware" — characterising the cluster's TTPs across manufacturing, education, financial-services, and other critical-infrastructure sectors, naming Akira as a high-volume RaaS strain with approximately 250 victim organisations and approximately $42M in confirmed ransom-payment proceeds through January 2024, and identifying the Akira-affiliate cohort's exploitation-of-public-facing-vulnerabilities and Cisco-VPN-without-MFA initial-access vectors ([cisa2024aa24109aakira]). Attribution at confirmed at the cluster level.
  • Megazord encryptor-variant introduction (late-2023). Sophos and Mandiant tracking documented the introduction of a Rust-based redevelopment of the Akira codebase ("Megazord" variant) in late-2023, continuing the broader 2022-to-2024 ransomware-sector migration toward memory-safe systems languages and the Conti-successor-cohort encryptor-architecture rotation pattern ([sophos2023akira]). Attribution at confirmed at the cluster level.
  • Cross-platform ESXi-and-Linux variant development (2023-2024). Akira's cross-platform encryptor builds for Windows / Linux / VMware ESXi from a shared codebase have been documented per multi-vendor tracking, with ESXi-host-targeted encryption a high-impact deployment pattern across mid-market enterprise IT victim cohorts. Attribution at confirmed at the cluster level per CISA AA24-109A.
  • Aggregate Akira metrics from [cisa2024aa24109aakira] (~250 victim organisations and ~$42M in confirmed ransom-payment proceeds through January 2024; cross-sector targeting across 12 of 16 critical-infrastructure sectors) and from [chainalysis2025ransomware] (sustained cluster-share across 2024-and-2025 in step with the post-Operation-Cronos LockBit-volume-collapse, post-ALPHV-exit-scam affiliate-displacement, and post-Black-Basta-internal-wind-down dispersal).
  • Worked examples for specific G16-mediated ransom-payment laundering flows are pending v0.x and will live under examples/ once the per-incident attribution surface stabilises sufficiently for the OAK confirmed / inferred-strong distinction.

Citations

  • [cisa2024aa24109aakira] — CISA / FBI / Europol EC3 / Netherlands NCSC-NL joint cyber-security advisory AA24-109A, "StopRansomware: Akira Ransomware," April 18, 2024.
  • [mandiant2024akira] — Mandiant tracker write-up on Akira operator-cohort attribution and Conti-codebase-related lineage.
  • [microsoftstorm1567] — Microsoft Threat Intelligence on Storm-1567 Akira-affiliated principal sub-cluster activity.
  • [sophos2023akira] — Sophos X-Ops late-2023 analysis of the Megazord Rust-based redevelopment of the Akira codebase.
  • [chainalysis2025ransomware] — Chainalysis 2024-recap ransomware report (referenced from G05 / G10 / G11 / G14 / G15 documentation as well); documents Akira cluster-share across 2024-and-2025.
  • [contileaks2022] — ContiLeaks insider leak (referenced from G11); foundational organisational-continuity context for the Conti-to-Akira dispersal pattern.
  • [ofac2022tornado] — sector-wide mixer-laundering enforcement context (referenced for the post-2022 ransomware-mixer-share decline, not for shared cluster identity).

Discussion

On the attribution-strength split. The Akira operator-cluster attribution is confirmed at the CISA-advisory layer — the April 2024 AA24-109A joint advisory by CISA, FBI, Europol EC3, and Netherlands NCSC-NL is the canonical multi-jurisdiction-coordinated public attribution document for the cluster — but is not OFAC-SDN-confirmed or DOJ-indictment-confirmed at the principal-operator level as of v0.1. This makes G16 a confirmed-by-CISA-advisory rather than confirmed-by-OFAC-SDN-designation case, structurally adjacent to OAK-G11 Black Basta and OAK-G15 RansomHub on the attribution-strength axis. OAK contributors writing G16-attributed examples should preserve this attribution-strength split per-incident, and should not infer OFAC-style asset-freeze-readiness from the underlying confirmed-grade cluster attribution. Attribution that specific affiliate operators are tied to specific real-world identities is inferred-strong per Mandiant / Microsoft / Sophos sub-cluster tracking; no DOJ unsealings of Akira-principal-operator indictments have been issued as of v0.1.

On the cluster-boundary distinction with OAK-G11 Black Basta. G16 (Akira) and G11 (Black Basta) are both Conti-codebase-related successor brands from the February-to-May 2022 ContiLeaks dispersal, but they are separate Conti-successor brands with distinct affiliate cohorts, distinct encryptor-codebase development trajectories, and distinct operating-pattern profiles. They differ along the encryptor-codebase-trajectory axis (Black Basta's encryptor lineage is Rust-and-C++-rooted from the cluster's launch in April 2022; Akira's lineage started C++-rooted from March 2023 and added the Megazord Rust-based variant in late-2023), the initial-access-vector axis (Black Basta's signature vector through 2022-and-2023 was the QakBot loader chain followed by the post-Operation-Duck-Hunt DarkGate / Pikabot pivot; Akira's signature vector is the exploitation-of-Cisco-VPN-without-MFA pattern), the attribution-surface axis (G11 is confirmed-by-CISA-advisory plus the February 2025 BlackBastaLeaks internal-chats archive; G16 is confirmed-by-CISA-advisory only), and the exit-dynamic axis (G11 internal-wound-down following internal-chats leak in late-2024-to-Q1-2025; G16 remains operationally active through v0.1). Defenders running affiliate-cluster-reuse attribution work across the ransomware sector should preserve this cluster-boundary distinction explicitly and treat G11 and G16 as separate per-cluster identities rather than aggregating them into a single Conti-successor cluster.

On the cluster-boundary distinction with OAK-G17 BlackByte and OAK-G18 Karakurt. G16, G17, and G18 are all Conti-codebase-related successor brands from the post-ContiLeaks dispersal substrate, but they emerged from different sub-cohorts within that dispersal: G17 BlackByte is a Conti-splinter cluster active from July 2021 (predating the ContiLeaks event by approximately seven months and operating through the dispersal window with continuity into the post-2022 period); G16 Akira launched in March 2023 (approximately ten months after the Conti-shutdown wind-down completed); and G18 Karakurt was Conti's data-extortion-only sub-team that became standalone after Conti's May 2022 dissolution. The three clusters differ in launch-window relationship to the ContiLeaks event, in encryptor-codebase trajectory, in operating-model (G16 and G17 run encryption-and-data-extortion double-extortion; G18 runs data-extortion-only), and in affiliate-cohort substrate. OAK contributors writing content across G16 / G17 / G18 should preserve the per-cluster identity discipline explicitly.

On the relationship to OAK-G03 Russian laundering infrastructure. G03 (Russian laundering infrastructure, Garantex / Grinex / A7A5 lineage) was a documented downstream venue for some fraction of Akira proceeds, with the G16 / G03 chain showing distribution across multiple non-KYC and lax-KYC venues consistent with the broader Russian-language commercial-criminal off-ramp profile. Defenders running OAK-G03 watchlists should expect some overlap with G16-attributed inflows, broadly consistent with the level of overlap expected with G11-attributed inflows.

On v0.x evolution. G16's 2026+ trajectory will depend on (a) whether further OFAC designations or DOJ indictments of Akira-principal-operators emerge, (b) whether the Cisco-VPN-without-MFA initial-access-vector pattern continues or shifts (sector-wide MFA-enforcement trends would compress the attack surface), (c) whether successor-encryptor-variant development continues the Rust-based redevelopment trajectory beyond Megazord, (d) whether cross-cluster-mobile affiliate movement across Akira and adjacent Conti-successor brands produces additional public-record affiliate-cluster-reuse instances per OAK-T8.001 methodology, and (e) whether a worked example of an Akira-attributed intrusion is added under examples/ once the per-flow attribution surface stabilises sufficiently. OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates.

Software used