Threat actor · OAK-G16
OAK-G16 — Akira Ransomware-as-a-Service operation
Description
OAK-G16 is the Akira ransomware-as-a-service operation: a Russian-language operator network that, between March 2023 and the present, has been one of the durable mid-volume RaaS strains in the post-Conti-dispersal window alongside OAK-G11 Black Basta and adjacent Conti-successor brands. The cluster is genuinely distinct from prior OAK Groups along multiple axes: from OAK-G05 LockBit, OAK-G10 ALPHV / BlackCat, and OAK-G14 Cl0p along the organisational-substrate axis (Akira is a Conti-codebase-related cluster from the post-ContiLeaks dispersal; LockBit, ALPHV, and Cl0p are independently-founded operating brands that pre-date or operate outside the Conti dispersal substrate); from OAK-G11 Black Basta along the Conti-successor sub-cohort axis (Akira and Black Basta are separate Conti-successor brands with distinct affiliate cohorts, distinct encryptor-codebase development trajectories, and distinct operating-pattern profiles, and OAK contributors writing G16-attributed content should preserve the cluster-boundary distinction with G11 explicitly to avoid over-aggregating Conti-successor activity into a single cluster); from OAK-G15 RansomHub along the organisational-substrate axis (G16 is post-ContiLeaks-dispersal; G15 is post-ALPHV-exit-scam absorber); from OAK-G17 BlackByte and OAK-G18 Karakurt along the Conti-successor sub-cohort axis (G16, G17, and G18 each carry distinct Conti-codebase-related lineage attestations from different sub-cohorts within the post-ContiLeaks dispersal); and from OAK-G12 Scattered Spider along the operating-brand-vs-affiliate-collective axis. Akira's inclusion in OAK is not because it is a crypto-native operator — its targets are overwhelmingly traditional-enterprise IT estates, with manufacturing, education, financial-services, and small-and-medium-business firms over-represented in the public victim record — but because cryptocurrency is the load-bearing payment-and-laundering rail of the entire RaaS business model and because the April 2024 CISA AA24-109A advisory established the cluster as a confirmed-grade RaaS attribution warranting per-cluster identity treatment alongside G05 / G10 / G11 / G14 / G15.
The operational model is a Conti-codebase-related ransomware-as-a-service split with several cluster-distinctive features. Akira's encryptor lineage is C++-and-Rust with cross-platform Windows / Linux / VMware ESXi builds; the cluster was an early adopter of the Rust-based redevelopment trajectory in mid-2023 with the Megazord variant (per Sophos late-2023 tracking), continuing the broader 2022-to-2024 ransomware-sector migration toward memory-safe systems languages. The cluster's Conti-codebase-related lineage is documented per multi-vendor tracking — overlap of operator personas across the post-ContiLeaks dispersal window, encryptor-architecture decisions consistent with Conti-codebase-related origins, and TTP-fingerprint signal (Cobalt Strike post-exploit, Empire / BloodHound lateral-movement, ESXi-host-targeted encryption) consistent with broader Conti-successor-cohort behaviour. Akira's signature initial-access vector through 2023-and-2024 was exploitation-of-Cisco-VPN-appliances-without-MFA: per CISA AA24-109A, Akira affiliates exploited Cisco ASA / FTD VPN appliances lacking multi-factor authentication as a recurring initial-access vector, with credential-spraying-and-brute-forcing of single-factor VPN accounts producing affiliate footholds across multi-sector victim cohorts. Affiliate-cut economics are reported in the mid-range of the major RaaS strains (industry-forensic estimates place Akira's affiliate split between LockBit's ~80% and ALPHV's ~85% baselines), with payments routed to affiliate-controlled wallets under the operator's payment-and-negotiation-portal supervision. The cluster's affiliate cohort is documented as overlapping with the broader Russian-language commercial-criminal substrate; multiple affiliate-cluster-reuse signals across Akira and adjacent Conti-successor brands have been documented per industry-forensic tracking, broadly consistent with the cross-cluster-mobile affiliate dynamic that defines the post-ContiLeaks dispersal window.
The cluster's defender-relevant signature is upstream-extraction-cluster with confirmed-grade public attribution at the CISA-advisory layer (rather than the OFAC-SDN layer), Conti-codebase-related lineage from the post-ContiLeaks dispersal, and signature exploitation-of-Cisco-VPN-without-MFA initial-access vector through 2023-and-2024. Per CISA AA24-109A the cluster had reached approximately 250 named-victim organisations and approximately $42M in confirmed ransom-payment proceeds through January 2024, with sustained victim-cohort growth across 2024-and-2025. Defenders running G16-tuned controls should expect (a) substantial overlap with anti-G11 Black Basta control-set design at the off-chain intrusion layer (loader chains, post-exploit tooling, lateral-movement, ESXi-host-targeting) and at the on-chain laundering-and-ransom-payment-flow layer (Russian-language commercial-criminal off-ramp profile), (b) cluster-distinctive Cisco-VPN-without-MFA initial-access-vector defense as an Akira-specific high-priority control surface, and (c) Conti-codebase-related operator-cluster-reuse signal across multiple successor brands per OAK-T8.001 attribution-side methodology.
Targeting profile
OAK-G16's victim profile is enterprise-IT rather than crypto-native, with sector concentration in manufacturing, education, financial services, professional services, healthcare, and small-and-medium-business — broadly consistent with broad-spectrum Conti-successor-cohort targeting:
- Manufacturing and industrial-sector firms — multiple regional manufacturers and industrial-supply-chain firms; manufacturing over-representation in the Akira record reflects the cluster's exploitation-of-Cisco-VPN-without-MFA initial-access vector against mid-market manufacturing-sector enterprise IT.
- Education-sector institutions — multiple U.S. and European universities, K-12 school districts, and education-adjacent organisations; education over-representation in the Akira record was a stated targeting-profile factor in CISA AA24-109A.
- Financial-services firms — multiple regional banks, credit unions, insurance firms, and financial-services-adjacent organisations; financial-sector targeting was less concentrated than in the G05 LockBit profile but consistent with broad-spectrum RaaS targeting.
- Professional-services and legal-sector firms — multiple law firms, accounting firms, and consulting firms; professional-services targeting reflects the cluster's mid-market-enterprise-IT focus.
- Healthcare-sector firms — multiple regional hospital systems, clinical networks, and healthcare-adjacent organisations; healthcare targeting was less concentrated than in the G10 ALPHV or G11 Black Basta profiles but consistent with cross-sector RaaS-cohort behaviour.
- Critical-infrastructure operators — present per CISA AA24-109A; sustained cross-sector targeting across 12 of 16 critical-infrastructure sectors.
- Cryptocurrency-industry firms as occasional targets — present but not the dominant target class; G16 is enterprise-extortion-led, not crypto-native-extraction-led.
- Downstream cryptocurrency users — only as secondary victims of the laundering rails the operation depends on.
Observed Techniques
OAK v0.1's Tactic catalog is on-chain-extraction-focused; Akira's intrusion surface (off-chain enterprise IT compromise via Cisco-VPN-without-MFA exploitation, Cobalt Strike post-exploit, Empire / BloodHound lateral-movement, ESXi-host-targeted encryption) sits outside that scope and is documented in CISA AA24-109A and the conventional cyber-threat-intel taxonomy. The on-chain Techniques observed in OAK-G16-attributable activity are concentrated on the payment-and-laundering side:
- OAK-T7.001 (Mixer-Routed Hop) — observed as a partial / earlier-stage component of the broader Akira laundering chain, with usage of Bitcoin mixers continuing the sector-wide post-Tornado-Cash-designation decline (
[ofac2022tornado]); per[chainalysis2025ransomware]mixer-share of ransomware-laundering volume continued falling across 2023-and-2024 and Akira followed the trend. - OAK-T7.002 (CEX Deposit-Address Layering) — the canonical Akira off-ramp for the Bitcoin portion of ransom payments, with affiliate-controlled deposit-address activity at non-KYC and lax-KYC venues a recurring industry-forensic signature; the cluster's downstream-laundering profile shows substantial overlap with the broader Russian-language commercial-criminal off-ramp surface.
- OAK-T7.003 (Cross-Asset / Cross-Chain Laundering) — observed in Akira laundering chains, with Bitcoin-to-stablecoin and Bitcoin-to-Monero conversion legs documented per industry-forensic write-ups.
- OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by Mandiant, Microsoft, Sophos, Chainalysis, and TRM Labs to maintain Akira affiliate-cluster identification across encryptor-version rotations (C++ → Megazord-Rust), across the Conti-shutdown / Akira-launch organisational-continuity window, and across cross-cluster-mobile affiliate movement to and from adjacent Conti-successor brands. The persistence of Bitcoin-funder-cluster identity across the Conti-to-Akira dispersal window is among the strongest indicators of operator continuity in the ransomware sector for the post-2022-cohort.
- OAK-T8.002 (Cross-Chain Operator Continuity) — observed in cross-cluster-mobile affiliate movement across Akira and adjacent Conti-successor brands per industry-forensic tracking.
- Adjacent / pre-incident vectors not in OAK v0.1 scope: off-chain initial access via exploitation of Cisco ASA / FTD VPN appliances lacking MFA (the cluster's signature 2023-and-2024 vector, per CISA AA24-109A), credential-spraying-and-brute-forcing, exploitation of public-facing vulnerabilities (Cisco AnyConnect, Veeam Backup, ESXi-host vulnerabilities), and Active-Directory-trust-relationship abuse for ESXi-host targeting; these are the canonical Akira-affiliate intrusion vectors and overlap substantially with the broader Conti-successor-cohort intrusion-vector profile while preserving the cluster-distinctive Cisco-VPN-without-MFA marker.
Observed Examples
No public incidents at v0.1 — worked examples pending per-incident forensic publication.
OAK v0.1 does not yet contain a worked example whose primary axis is an Akira target; the on-chain angle of G16 is the laundering of ransom payments rather than direct crypto-firm intrusion, and the cluster's most defender-relevant payment-tracing case is on the watch-list for v0.x worked-example coverage. The high-salience public-record events anchoring the cluster:
- CISA / FBI / Europol EC3 / NCSC-NL AA24-109A joint advisory (April 18, 2024). "StopRansomware: Akira Ransomware" — characterising the cluster's TTPs across manufacturing, education, financial-services, and other critical-infrastructure sectors, naming Akira as a high-volume RaaS strain with approximately 250 victim organisations and approximately $42M in confirmed ransom-payment proceeds through January 2024, and identifying the Akira-affiliate cohort's exploitation-of-public-facing-vulnerabilities and Cisco-VPN-without-MFA initial-access vectors (
[cisa2024aa24109aakira]). Attribution at confirmed at the cluster level. - Megazord encryptor-variant introduction (late-2023). Sophos and Mandiant tracking documented the introduction of a Rust-based redevelopment of the Akira codebase ("Megazord" variant) in late-2023, continuing the broader 2022-to-2024 ransomware-sector migration toward memory-safe systems languages and the Conti-successor-cohort encryptor-architecture rotation pattern (
[sophos2023akira]). Attribution at confirmed at the cluster level. - Cross-platform ESXi-and-Linux variant development (2023-2024). Akira's cross-platform encryptor builds for Windows / Linux / VMware ESXi from a shared codebase have been documented per multi-vendor tracking, with ESXi-host-targeted encryption a high-impact deployment pattern across mid-market enterprise IT victim cohorts. Attribution at confirmed at the cluster level per CISA AA24-109A.
- Aggregate Akira metrics from
[cisa2024aa24109aakira](~250 victim organisations and ~$42M in confirmed ransom-payment proceeds through January 2024; cross-sector targeting across 12 of 16 critical-infrastructure sectors) and from[chainalysis2025ransomware](sustained cluster-share across 2024-and-2025 in step with the post-Operation-Cronos LockBit-volume-collapse, post-ALPHV-exit-scam affiliate-displacement, and post-Black-Basta-internal-wind-down dispersal). - Worked examples for specific G16-mediated ransom-payment laundering flows are pending v0.x and will live under
examples/once the per-incident attribution surface stabilises sufficiently for the OAK confirmed / inferred-strong distinction.
Citations
[cisa2024aa24109aakira]— CISA / FBI / Europol EC3 / Netherlands NCSC-NL joint cyber-security advisory AA24-109A, "StopRansomware: Akira Ransomware," April 18, 2024.[mandiant2024akira]— Mandiant tracker write-up on Akira operator-cohort attribution and Conti-codebase-related lineage.[microsoftstorm1567]— Microsoft Threat Intelligence on Storm-1567 Akira-affiliated principal sub-cluster activity.[sophos2023akira]— Sophos X-Ops late-2023 analysis of the Megazord Rust-based redevelopment of the Akira codebase.[chainalysis2025ransomware]— Chainalysis 2024-recap ransomware report (referenced from G05 / G10 / G11 / G14 / G15 documentation as well); documents Akira cluster-share across 2024-and-2025.[contileaks2022]— ContiLeaks insider leak (referenced from G11); foundational organisational-continuity context for the Conti-to-Akira dispersal pattern.[ofac2022tornado]— sector-wide mixer-laundering enforcement context (referenced for the post-2022 ransomware-mixer-share decline, not for shared cluster identity).
Discussion
On the attribution-strength split. The Akira operator-cluster attribution is confirmed at the CISA-advisory layer — the April 2024 AA24-109A joint advisory by CISA, FBI, Europol EC3, and Netherlands NCSC-NL is the canonical multi-jurisdiction-coordinated public attribution document for the cluster — but is not OFAC-SDN-confirmed or DOJ-indictment-confirmed at the principal-operator level as of v0.1. This makes G16 a confirmed-by-CISA-advisory rather than confirmed-by-OFAC-SDN-designation case, structurally adjacent to OAK-G11 Black Basta and OAK-G15 RansomHub on the attribution-strength axis. OAK contributors writing G16-attributed examples should preserve this attribution-strength split per-incident, and should not infer OFAC-style asset-freeze-readiness from the underlying confirmed-grade cluster attribution. Attribution that specific affiliate operators are tied to specific real-world identities is inferred-strong per Mandiant / Microsoft / Sophos sub-cluster tracking; no DOJ unsealings of Akira-principal-operator indictments have been issued as of v0.1.
On the cluster-boundary distinction with OAK-G11 Black Basta. G16 (Akira) and G11 (Black Basta) are both Conti-codebase-related successor brands from the February-to-May 2022 ContiLeaks dispersal, but they are separate Conti-successor brands with distinct affiliate cohorts, distinct encryptor-codebase development trajectories, and distinct operating-pattern profiles. They differ along the encryptor-codebase-trajectory axis (Black Basta's encryptor lineage is Rust-and-C++-rooted from the cluster's launch in April 2022; Akira's lineage started C++-rooted from March 2023 and added the Megazord Rust-based variant in late-2023), the initial-access-vector axis (Black Basta's signature vector through 2022-and-2023 was the QakBot loader chain followed by the post-Operation-Duck-Hunt DarkGate / Pikabot pivot; Akira's signature vector is the exploitation-of-Cisco-VPN-without-MFA pattern), the attribution-surface axis (G11 is confirmed-by-CISA-advisory plus the February 2025 BlackBastaLeaks internal-chats archive; G16 is confirmed-by-CISA-advisory only), and the exit-dynamic axis (G11 internal-wound-down following internal-chats leak in late-2024-to-Q1-2025; G16 remains operationally active through v0.1). Defenders running affiliate-cluster-reuse attribution work across the ransomware sector should preserve this cluster-boundary distinction explicitly and treat G11 and G16 as separate per-cluster identities rather than aggregating them into a single Conti-successor cluster.
On the cluster-boundary distinction with OAK-G17 BlackByte and OAK-G18 Karakurt. G16, G17, and G18 are all Conti-codebase-related successor brands from the post-ContiLeaks dispersal substrate, but they emerged from different sub-cohorts within that dispersal: G17 BlackByte is a Conti-splinter cluster active from July 2021 (predating the ContiLeaks event by approximately seven months and operating through the dispersal window with continuity into the post-2022 period); G16 Akira launched in March 2023 (approximately ten months after the Conti-shutdown wind-down completed); and G18 Karakurt was Conti's data-extortion-only sub-team that became standalone after Conti's May 2022 dissolution. The three clusters differ in launch-window relationship to the ContiLeaks event, in encryptor-codebase trajectory, in operating-model (G16 and G17 run encryption-and-data-extortion double-extortion; G18 runs data-extortion-only), and in affiliate-cohort substrate. OAK contributors writing content across G16 / G17 / G18 should preserve the per-cluster identity discipline explicitly.
On the relationship to OAK-G03 Russian laundering infrastructure. G03 (Russian laundering infrastructure, Garantex / Grinex / A7A5 lineage) was a documented downstream venue for some fraction of Akira proceeds, with the G16 / G03 chain showing distribution across multiple non-KYC and lax-KYC venues consistent with the broader Russian-language commercial-criminal off-ramp profile. Defenders running OAK-G03 watchlists should expect some overlap with G16-attributed inflows, broadly consistent with the level of overlap expected with G11-attributed inflows.
On v0.x evolution. G16's 2026+ trajectory will depend on (a) whether further OFAC designations or DOJ indictments of Akira-principal-operators emerge, (b) whether the Cisco-VPN-without-MFA initial-access-vector pattern continues or shifts (sector-wide MFA-enforcement trends would compress the attack surface), (c) whether successor-encryptor-variant development continues the Rust-based redevelopment trajectory beyond Megazord, (d) whether cross-cluster-mobile affiliate movement across Akira and adjacent Conti-successor brands produces additional public-record affiliate-cluster-reuse instances per OAK-T8.001 methodology, and (e) whether a worked example of an Akira-attributed intrusion is added under examples/ once the per-flow attribution surface stabilises sufficiently. OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates.