OAK — OnChain Attack Knowledge

Threat actor · OAK-G17

OAK-G17 — BlackByte Ransomware-as-a-Service operation

Aliases
BlackByte (operating brand on Russian-language criminal forums and the cluster's Tor-hosted leak site, July 2021 → present, with multi-language encryptor-variant development across the cluster's operating window), Hecamede (some early industry-forensic write-ups; minority usage), and the Conti-splinter operator-cohort identified across multiple industry-forensic write-ups as carrying Conti-codebase-related lineage from the broader Conti-organisational substrate into the BlackByte operating brand. BlackByte's Conti-splinter lineage is separate from but parallel to OAK-G11 Black Basta, OAK-G16 Akira, and OAK-G18 Karakurt — BlackByte is the earliest-launching of the major Conti-codebase-related successor brands tracked in OAK v0.1, predating the February-to-May 2022 ContiLeaks event by approximately seven months and operating through the dispersal window with continuity into the post-2022 period, which gives the cluster a structurally distinct relationship to the post-ContiLeaks dispersal substrate compared to the post-2022-launching Black Basta and Akira clusters. For OAK-G17 purposes the cluster is the BlackByte RaaS operation — the core operator network behind the BlackByte encryptor (with multi-language variant development across .NET / C++ / Go through the cluster's operating window, and the Go-language variant a defender-relevant marker tracked through 2022-and-2023 industry-forensic write-ups), the affiliate-management infrastructure, and the leak-site operation — considered jointly with the Conti-codebase-related operator-cohort substrate from which BlackByte emerged.
First observed in crypto
July 2021 (BlackByte-branded encryptor first observed in incident-response engagements in July 2021, with cluster-attributed intrusions documented from mid-2021 onward; the RaaS / ransomware operating model with Bitcoin-and-Monero-denominated ransom payments has been the operational default since inception, with the cluster active across the entire post-2021 ransomware-evolution window through v0.1).
Attribution status
confirmed at the cluster-and-tooling level — joint FBI / U.S. Secret Service cyber-security advisory CU-000167-MW (Feb 11 2022 FBI Flash) and the joint FBI / U.S. Secret Service Joint Cybersecurity Advisory TLP:WHITE on BlackByte Ransomware (the same February 2022 advisory cycle frequently referenced by industry-forensic write-ups as "TA22-039A-equivalent" though the canonical CISA advisory tracker uses the FBI Flash format rather than the AA-NNNNN tracker number) ([fbi2022blackbyteflash]), characterising the cluster's TTPs across U.S. critical-infrastructure entities including the February 2022 attack against the San Francisco 49ers professional sports franchise; sustained multi-vendor industry-forensic corroboration (Mandiant tracking, Microsoft Threat Intelligence, Sophos X-Ops, Trustwave SpiderLabs, Symantec Threat Hunter Team, Recorded Future, Coveware, Chainalysis, TRM Labs) characterising the multi-language encryptor lineage, the Russian-language operator-forum substrate, the Conti-splinter lineage attestation, and sustained 2022-and-2023 cross-platform encryptor-variant development including the Go-language variant; Trustwave SpiderLabs late-2021 reporting on the BlackByte encryptor's symmetric-key-reuse implementation flaw that allowed the publication of a free decryptor ([trustwave2021blackbyte]); subsequent BlackByte-encryptor redevelopment to address the cryptographic flaw and extend the cross-platform variant set. The Conti-splinter lineage claim is inferred-strong — overlap of operator personas, encryptor-architecture decisions, and TTP-fingerprint signal across the Conti-organisational substrate are documented across Mandiant, Microsoft, and Sophos tracking but the cluster has not been individually OFAC-designated or DOJ-indicted at the principal-operator level as of v0.1. Attribution that specific ransom-payment flows trace to specific affiliate wallets within the BlackByte cluster is inferred-strong from industry forensic providers.
Active
yes as of v0.1 — BlackByte-branded extortion activity continued through 2024-and-2025 with sustained leak-site operation, continued cross-platform encryptor-variant development, and continued ransom-payment flow tracked by industry-forensic providers, though at lower victim-count throughput than the dominant 2024 RaaS strains (RansomHub, LockBit residuals, Akira). Per [chainalysis2025ransomware] BlackByte's market-share among RaaS strains has been sustained in the long-tail mid-volume RaaS-strain segment across 2024-and-2025, with the cluster positioned as one of the most operationally durable Conti-codebase-related successor brands by total operating-window length (July 2021 → present, exceeding four years by v0.1).

Description

OAK-G17 is the BlackByte ransomware-as-a-service operation: a Russian-language operator network that, between July 2021 and the present, has been the most operationally durable of the Conti-codebase-related successor brands by total operating-window length and is the canonical pre-ContiLeaks Conti-splinter cluster on the OAK roster. The cluster is genuinely distinct from prior OAK Groups along multiple axes: from OAK-G05 LockBit, OAK-G10 ALPHV / BlackCat, and OAK-G14 Cl0p along the organisational-substrate axis (BlackByte is a Conti-codebase-related Conti-splinter cluster; LockBit, ALPHV, and Cl0p are independently-founded operating brands that pre-date or operate outside the Conti dispersal substrate); from OAK-G11 Black Basta and OAK-G16 Akira along the Conti-successor sub-cohort axis (BlackByte launched in July 2021, predating the ContiLeaks event by approximately seven months and operating through the dispersal window with continuity into the post-2022 period; Black Basta and Akira launched in April 2022 and March 2023 respectively, after the Conti-shutdown wind-down completed) — BlackByte's pre-ContiLeaks-launch position gives the cluster a structurally distinct relationship to the post-ContiLeaks dispersal substrate; from OAK-G15 RansomHub along the organisational-substrate axis (G17 is Conti-codebase-related; G15 is post-ALPHV-exit-scam absorber); from OAK-G18 Karakurt along the Conti-successor sub-cohort axis (Karakurt was Conti's data-extortion-only sub-team that became standalone after Conti's May 2022 dissolution; BlackByte is an earlier-launching encryption-and-data-extortion Conti-splinter); and from OAK-G12 Scattered Spider along the operating-brand-vs-affiliate-collective axis. BlackByte's inclusion in OAK is not because it is a crypto-native operator — its targets are overwhelmingly traditional-enterprise IT estates and U.S. critical-infrastructure entities — but because cryptocurrency is the load-bearing payment-and-laundering rail of the entire RaaS business model, because the February 2022 FBI Flash and Joint Cybersecurity Advisory established the cluster as a confirmed-grade RaaS attribution against U.S. critical-infrastructure targeting, and because the cluster's multi-language encryptor lineage (including the defender-relevant Go-language variant) and four-plus-year operating-window durability warrant per-cluster identity treatment alongside G05 / G10 / G11 / G14 / G15 / G16.

The operational model is a Conti-codebase-related ransomware-as-a-service split with several cluster-distinctive features. BlackByte's encryptor lineage shows multi-language variant development across the cluster's operating window — early variants in .NET, subsequent C++ variants, and the Go-language variant tracked through 2022-and-2023 industry-forensic write-ups — with the Go-language variant a defender-relevant marker for the cluster's cross-platform-and-cross-architecture deployment posture. The cluster's first publicly-tracked variant (in late-2021) had a symmetric-key-reuse implementation flaw that Trustwave SpiderLabs identified and exploited to publish a free decryptor ([trustwave2021blackbyte]); subsequent BlackByte-encryptor redevelopment addressed the cryptographic flaw and extended the cross-platform variant set, with the operator persona explicitly responding to the decryptor release by accelerating the variant-rotation tempo. The cluster's Conti-codebase-related lineage is documented per multi-vendor tracking — overlap of operator personas across the Conti-organisational substrate, encryptor-architecture decisions consistent with Conti-codebase-related origins, and TTP-fingerprint signal (Cobalt Strike post-exploit, Empire / BloodHound lateral-movement, ESXi-host-targeted encryption) consistent with broader Conti-organisational-cohort behaviour. Affiliate-cut economics are documented in the conventional RaaS-mid-range per industry-forensic estimates, with payments routed to affiliate-controlled wallets under the operator's payment-and-negotiation-portal supervision. The cluster's signature 2021-and-2022 initial-access vectors included exploitation of public-facing vulnerabilities (Microsoft Exchange ProxyShell-class CVE-2021-34473 / CVE-2021-34523 / CVE-2021-31207, Citrix vulnerabilities, exposed-RDP) and Active-Directory-trust-relationship abuse for ESXi-host targeting; the cluster's 2023-and-2024 vector profile evolved alongside the broader RaaS-cohort intrusion-vector evolution.

The cluster's defender-relevant signature is upstream-extraction-cluster with confirmed-grade public attribution at the FBI-Flash-and-Joint-Cybersecurity-Advisory layer (rather than the OFAC-SDN layer), Conti-codebase-related Conti-splinter lineage from the pre-ContiLeaks operating window, multi-language encryptor-variant development, and four-plus-year operating-window durability. The February 2022 attack against the San Francisco 49ers professional sports franchise — encrypted on Super Bowl LVI weekend with the leak-site posting timed for media-cycle impact — was the cluster's highest-salience single-victim public-record case and was specifically cited in the FBI Flash as the basis for the joint-advisory escalation tempo against U.S. critical-infrastructure targeting. Defenders running G17-tuned controls should expect (a) substantial overlap with anti-G11 Black Basta and anti-G16 Akira control-set design at the off-chain intrusion layer (Cobalt Strike post-exploit, Empire / BloodHound lateral-movement, ESXi-host-targeting) and at the on-chain laundering-and-ransom-payment-flow layer (Russian-language commercial-criminal off-ramp profile), (b) cluster-distinctive multi-language encryptor-variant tracking (including the Go-language variant) as a high-priority detection-engineering surface, and (c) Conti-codebase-related operator-cluster-reuse signal across multiple successor brands per OAK-T8.001 attribution-side methodology.

Targeting profile

OAK-G17's victim profile is enterprise-IT rather than crypto-native, with sector concentration in U.S. critical-infrastructure entities, financial services, government / public sector, manufacturing, and education — broadly consistent with the FBI-Flash-stated targeting profile and with broader Conti-codebase-related-cohort behaviour:

  • U.S. critical-infrastructure entities — multiple U.S. critical-infrastructure-sector targets per the February 2022 FBI Flash, including financial-services, food-and-agriculture, and government-facilities targets; critical-infrastructure over-representation in the BlackByte record was a stated escalation factor in the joint-advisory tempo.
  • U.S. professional-sports and media organisations — San Francisco 49ers (February 2022, the canonical high-salience case; Super-Bowl-weekend timing for media-cycle impact); professional-sports targeting was a cluster-distinctive marker in the early operating window.
  • Manufacturing and industrial-sector firms — multiple regional manufacturers and industrial-supply-chain firms; manufacturing over-representation reflects the broader RaaS-cohort targeting profile.
  • Financial-services firms — multiple regional banks, credit unions, and financial-services-adjacent organisations.
  • Government and public-sector organisations — multiple U.S. state and municipal governments and education-sector targets.
  • Cryptocurrency-industry firms as occasional targets — present but not the dominant target class; G17 is enterprise-extortion-led, not crypto-native-extraction-led.
  • Downstream cryptocurrency users — only as secondary victims of the laundering rails the operation depends on.

Observed Techniques

OAK v0.1's Tactic catalog is on-chain-extraction-focused; BlackByte's intrusion surface (off-chain enterprise IT compromise via exploitation of public-facing vulnerabilities, Cobalt Strike post-exploit, Empire / BloodHound lateral-movement, ESXi-host-targeted encryption) sits outside that scope and is documented in the February 2022 FBI Flash and the conventional cyber-threat-intel taxonomy. The on-chain Techniques observed in OAK-G17-attributable activity are concentrated on the payment-and-laundering side:

  • OAK-T7.001 (Mixer-Routed Hop) — observed as a partial / earlier-stage component of the broader BlackByte laundering chain, with usage of Bitcoin mixers continuing the sector-wide post-Tornado-Cash-designation decline ([ofac2022tornado]); per [chainalysis2025ransomware] mixer-share of ransomware-laundering volume continued falling across 2023-and-2024 and BlackByte followed the trend.
  • OAK-T7.002 (CEX Deposit-Address Layering) — the canonical post-2023 BlackByte off-ramp for the Bitcoin portion of ransom payments, with affiliate-controlled deposit-address activity at non-KYC and lax-KYC venues a recurring industry-forensic signature; the cluster's downstream-laundering profile shows substantial overlap with the broader Russian-language commercial-criminal off-ramp surface.
  • OAK-T7.003 (Cross-Asset / Cross-Chain Laundering) — observed in BlackByte laundering chains, with Bitcoin-to-stablecoin and Bitcoin-to-Monero conversion legs documented per industry-forensic write-ups.
  • OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by Mandiant, Microsoft, Sophos, Trustwave, Chainalysis, and TRM Labs to maintain BlackByte affiliate-cluster identification across encryptor-version rotations (.NET → C++ → Go), across the Conti-organisational-substrate continuity window, and across cross-cluster-mobile affiliate movement to and from adjacent Conti-codebase-related successor brands. The persistence of Bitcoin-funder-cluster identity across the cluster's four-plus-year operating window — including across the 2022 ContiLeaks dispersal — is among the strongest indicators of operator continuity in the ransomware sector for the pre-2022-cohort.
  • OAK-T8.002 (Cross-Chain Operator Continuity) — observed in cross-cluster-mobile affiliate movement across BlackByte and adjacent Conti-codebase-related successor brands per industry-forensic tracking.
  • Adjacent / pre-incident vectors not in OAK v0.1 scope: off-chain initial access via exploitation of Microsoft Exchange ProxyShell-class CVEs (CVE-2021-34473 / CVE-2021-34523 / CVE-2021-31207) in 2021-and-2022, exploitation of Citrix vulnerabilities, exposed-RDP exploitation, exploitation of public-facing vulnerabilities across the cluster's evolving operating window, and Active-Directory-trust-relationship abuse for ESXi-host targeting; these are the canonical BlackByte-affiliate intrusion vectors and overlap substantially with the broader Conti-codebase-related-cohort intrusion-vector profile.

Observed Examples

No public incidents at v0.1 — worked examples pending per-incident forensic publication.

OAK v0.1 does not yet contain a worked example whose primary axis is a BlackByte target; the on-chain angle of G17 is the laundering of ransom payments rather than direct crypto-firm intrusion, and the cluster's most defender-relevant payment-tracing case is on the watch-list for v0.x worked-example coverage. The high-salience public-record events anchoring the cluster:

  • FBI / U.S. Secret Service Joint Cybersecurity Advisory and FBI Flash CU-000167-MW (February 11, 2022). Joint cyber-security advisory characterising BlackByte TTPs across U.S. critical-infrastructure entities and naming the February 2022 San Francisco 49ers attack ([fbi2022blackbyteflash]). Attribution at confirmed at the cluster level.
  • San Francisco 49ers ransomware incident (February 2022). BlackByte-attributed encryption of the 49ers IT estate on Super Bowl LVI weekend, with leak-site posting timed for media-cycle impact; the canonical high-salience single-victim public-record case for the cluster ([espn2022blackbyte49ers]). Attribution at confirmed at the cluster level.
  • Trustwave SpiderLabs decryptor publication (October 2021). Trustwave SpiderLabs identified a symmetric-key-reuse implementation flaw in the early BlackByte encryptor and published a free decryptor; the cluster operator persona responded by accelerating the variant-rotation tempo and addressing the cryptographic flaw in subsequent variants ([trustwave2021blackbyte]). Attribution at confirmed at the cluster level. The episode is a defender-relevant cluster-history marker for the encryptor-cryptographic-flaw → decryptor-publication → variant-rotation dynamic that has recurred across the ransomware sector.
  • Multi-language encryptor-variant development (2021-2024). BlackByte's encryptor-variant rotation across .NET / C++ / Go languages through 2021-and-2024 has been documented per multi-vendor tracking, with the Go-language variant a defender-relevant marker tracked through 2022-and-2023 industry-forensic write-ups ([mandiant2022blackbyte], [microsoft2022blackbyte]). Attribution at confirmed at the cluster level.
  • Aggregate BlackByte metrics from [fbi2022blackbyteflash] (cross-sector targeting against U.S. critical-infrastructure entities) and from [chainalysis2025ransomware] (sustained mid-volume cluster-share across 2024-and-2025 in the long-tail RaaS-strain segment).
  • Worked examples for specific G17-mediated ransom-payment laundering flows are pending v0.x and will live under examples/ once the per-incident attribution surface stabilises sufficiently for the OAK confirmed / inferred-strong distinction.

Citations

  • [fbi2022blackbyteflash] — FBI / U.S. Secret Service Joint Cybersecurity Advisory and FBI Flash CU-000167-MW on BlackByte Ransomware, February 11, 2022.
  • [mandiant2022blackbyte] — Mandiant tracker write-up on BlackByte operator-cohort attribution and Conti-codebase-related lineage.
  • [microsoft2022blackbyte] — Microsoft Threat Intelligence on BlackByte affiliate sub-cluster activity and multi-language encryptor-variant tracking.
  • [sophos2022blackbyte] — Sophos X-Ops analysis of the BlackByte Go-language encryptor variant and cross-platform deployment posture.
  • [trustwave2021blackbyte] — Trustwave SpiderLabs late-2021 analysis of the BlackByte encryptor symmetric-key-reuse implementation flaw and the published decryptor.
  • [espn2022blackbyte49ers] — ESPN reporting on the February 2022 San Francisco 49ers BlackByte ransomware incident.
  • [chainalysis2025ransomware] — Chainalysis 2024-recap ransomware report (referenced from G05 / G10 / G11 / G14 / G15 / G16 documentation as well); documents BlackByte cluster-share across 2024-and-2025.
  • [contileaks2022] — ContiLeaks insider leak (referenced from G11); foundational organisational-continuity context for the broader Conti-organisational substrate from which BlackByte emerged.
  • [ofac2022tornado] — sector-wide mixer-laundering enforcement context (referenced for the post-2022 ransomware-mixer-share decline, not for shared cluster identity).

Discussion

On the attribution-strength split. The BlackByte operator-cluster attribution is confirmed at the FBI-Flash-and-Joint-Cybersecurity-Advisory layer — the February 2022 FBI / U.S. Secret Service joint advisory and FBI Flash CU-000167-MW are the canonical national-government public attribution documents for the cluster — but is not OFAC-SDN-confirmed or DOJ-indictment-confirmed at the principal-operator level as of v0.1. This makes G17 a confirmed-by-FBI-Flash-and-Joint-Cybersecurity-Advisory rather than confirmed-by-OFAC-SDN-designation case, structurally adjacent to OAK-G11 Black Basta, OAK-G15 RansomHub, and OAK-G16 Akira on the attribution-strength axis. OAK contributors writing G17-attributed examples should preserve this attribution-strength split per-incident, and should not infer OFAC-style asset-freeze-readiness from the underlying confirmed-grade cluster attribution.

On the cluster-boundary distinction with OAK-G11 Black Basta and OAK-G16 Akira. G17 (BlackByte), G11 (Black Basta), and G16 (Akira) are all Conti-codebase-related successor brands but they emerged from different sub-cohorts within the broader Conti-organisational substrate, with structurally distinct relationships to the February-to-May 2022 ContiLeaks event: G17 BlackByte launched in July 2021, predating the ContiLeaks event by approximately seven months and operating through the dispersal window with continuity into the post-2022 period (the cluster is therefore a pre-ContiLeaks Conti-splinter rather than a post-ContiLeaks dispersal product); G11 Black Basta launched in April 2022, immediately following the Conti-shutdown wind-down and inheriting substantial Conti-organisational continuity into the post-leak period; G16 Akira launched in March 2023, approximately ten months after the Conti-shutdown wind-down completed, with Conti-codebase-related lineage attestation but at a longer remove from the immediate dispersal substrate. The three clusters differ in launch-window relationship to the ContiLeaks event, in encryptor-codebase trajectory (G17 multi-language .NET / C++ / Go; G11 Rust-and-C++; G16 C++ → Megazord-Rust), in operating-window length (G17 four-plus years through v0.1; G11 ~2.5 years before internal wind-down; G16 ~2.5 years through v0.1), and in attribution-surface composition. OAK contributors writing content across G11 / G16 / G17 should preserve the per-cluster identity discipline explicitly and should not aggregate the three Conti-successor brands into a single Conti-cluster.

On the cluster-boundary distinction with OAK-G18 Karakurt. G17 (BlackByte) and G18 (Karakurt) are both Conti-codebase-related successor brands but differ along the operating-model axis (G17 runs encryption-and-data-extortion double-extortion; G18 runs data-extortion-only without encryption deployment, structurally similar to the OAK-G14 Cl0p mid-2023 pivot but adopted from G18's launch in May 2021), the Conti-organisational-substrate-relationship axis (G17 is a Conti-splinter cluster that operated alongside Conti through the dispersal window; G18 was Conti's data-extortion-only sub-team that became standalone after Conti's May 2022 dissolution — a structurally different organisational-continuity attestation), and the target-vector axis (G17 deploys ESXi-and-Windows multi-platform encryption; G18 runs data-exfiltration-without-encryption). The two clusters should not be conflated; their per-cluster identity discipline matters for defender-side affiliate-cluster-reuse attribution work and for incident-response runbook design.

On the multi-language encryptor-variant-rotation pattern. BlackByte's multi-language encryptor-variant rotation across .NET / C++ / Go through the cluster's operating window is among the most aggressive variant-rotation tempos in the major-RaaS-strain public record. The October 2021 Trustwave SpiderLabs decryptor publication is the publicly-documented inflection point — the operator persona responded to the decryptor release by accelerating the variant-rotation tempo and addressing the cryptographic flaw in subsequent variants — and the resulting encryptor-cryptographic-flaw → decryptor-publication → variant-rotation dynamic is a cluster-distinctive operator-behaviour marker that has recurred at lower intensity across the broader ransomware sector. Defenders running detection-engineering work against BlackByte should expect sustained variant-rotation tempo and should treat the multi-language variant set as a high-priority detection-engineering surface.

On the relationship to OAK-G03 Russian laundering infrastructure. G03 (Russian laundering infrastructure, Garantex / Grinex / A7A5 lineage) was a documented downstream venue for some fraction of BlackByte proceeds, with the G17 / G03 chain showing distribution across multiple non-KYC and lax-KYC venues consistent with the broader Russian-language commercial-criminal off-ramp profile. Defenders running OAK-G03 watchlists should expect some overlap with G17-attributed inflows.

On v0.x evolution. G17's 2026+ trajectory will depend on (a) whether further OFAC designations or DOJ indictments of BlackByte-principal-operators emerge, (b) whether the multi-language encryptor-variant-rotation tempo continues or stabilises, (c) whether the cluster's sustained four-plus-year operating-window durability extends through 2026-and-beyond (positioning BlackByte as one of the most-durable Russian-language Conti-codebase-related successor brands), (d) whether cross-cluster-mobile affiliate movement across BlackByte and adjacent Conti-codebase-related successor brands produces additional public-record affiliate-cluster-reuse instances per OAK-T8.001 methodology, and (e) whether a worked example of a BlackByte-attributed intrusion is added under examples/ once the per-flow attribution surface stabilises sufficiently. OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates.

Software used