Threat actor · OAK-G18
OAK-G18 — Karakurt extortion-only data-theft operation
Description
OAK-G18 is the Karakurt extortion-only data-theft operation: a Russian-speaking operator cluster that, between mid-2021 and the present, has produced the canonical encryption-free data-theft-and-extortion operating-model worked example in the public record and is the prototype of the data-extortion-only operating model that subsequently spread to OAK-G14 Cl0p (mid-2023 pivot), BianLian, RansomHouse, and adjacent clusters. The cluster is genuinely distinct from prior OAK Conti-successor entries along multiple axes: from OAK-G11 Black Basta, OAK-G16 Akira, and OAK-G17 BlackByte along the operating-model axis (G18 deploys no encryption and operates entirely on the data-disclosure-threat negotiation surface, structurally distinct from the encryption-and-data-extortion double-extortion model of G11 / G16 / G17); from OAK-G14 Cl0p along the operating-model-emergence axis (G18 was born data-extortion-only in 2021; G14 pivoted to data-extortion-only in 2023 from a prior encryption-and-data-extortion model); and from OAK-G05 LockBit, OAK-G10 ALPHV / BlackCat along the operator-cohort-substrate axis (G18 is Conti / Wizard Spider cohort-substrate; G05 / G10 are independently founded RaaS clusters). Karakurt's inclusion in OAK is because cryptocurrency is the load-bearing payment-and-laundering rail of the entire data-extortion business model, because the cluster is the operating-model novelty progenitor in the public record, and because the Conti-cohort-continuity attribution at the on-chain layer makes Karakurt one of the cleanest cases for tracking operator-cohort continuity across Conti-successor brand rotation.
The operational model is a Russian-speaking operator-cohort-led data-extortion operation with several cluster-distinctive features. Karakurt emerged in mid-2021 as a Conti-side-channel data-extortion-only sub-team — it operated within the broader Conti / Wizard Spider operator-cohort substrate while Conti was still active, taking on intrusions where the Conti operating-cohort assessed that encryption-deployment would be operationally disadvantageous (most commonly because the target's incident-response posture was strong enough that encryption would be detected and mitigated quickly, or because the data-disclosure-threat alone would produce sufficient negotiating leverage). The cluster survived the May 2022 Conti dissolution as a standalone operating brand and continued operating through 2022–2025; the CISA / FBI / Treasury / FinCEN AA22-152A advisory (June 2022) characterised Karakurt's intrusion-and-extortion pattern, the cluster's operator-cohort substrate, and the data-extortion-only operating-model signature. The intrusion-side operational pattern is conventional Conti-cohort tradecraft — initial access via phishing-and-malware-loader chains (TrickBot / IcedID / BazarLoader / Cobalt Strike historically; post-Conti-cohort the loader rotation followed the broader sector evolution), Cobalt Strike post-exploitation, Mimikatz / domain-admin credential theft, and lateral-movement-via-RDP-and-SMB — but the cluster's extraction-and-monetisation phase is encryption-free: data is exfiltrated via commodity tooling (rclone for cloud-storage exfiltration, Mega.io and Filezilla for direct exfiltration, FreeFileSync for periodic cohort-aggregation), the exfiltrated data is staged for publication on the Karakurt Lair leak site, and the negotiation portal communicates the disclosure-threat to the victim along with a cryptocurrency-payment instruction. The cluster's operator cohort is Russian-speaking and is documented in CISA AA22-152A as overlapping at the personnel level with the Conti / Wizard Spider cohort; per Mandiant and Chainalysis cross-cohort analysis, Karakurt affiliate wallet clusters share funder-address structure with documented Conti-era affiliate clusters, supporting the Conti-cohort-continuity attribution at the on-chain layer.
The cluster's defender-relevant signature is Conti-successor cohort with confirmed-grade public attribution at the CISA-advisory layer, encryption-free data-theft-and-extortion operating-model signature, and an operator-cohort-substrate that overlaps at the personnel-and-wallet-cluster level with the broader Conti-successor diaspora. The data-extortion-only operating model is the cluster's load-bearing operating-pattern novelty: Karakurt is the prototype in the public record of the data-extortion-only model that subsequently spread to OAK-G14 Cl0p (mid-2023 pivot), BianLian, RansomHouse, and adjacent clusters. Defenders running anti-G18 control sets should treat the cluster as a Conti-successor with the encryption-deployment phase removed; intrusion-and-credential-theft control surfaces remain identical to anti-Conti / anti-Black-Basta / anti-Akira / anti-BlackByte control surfaces, but encryption-detection-and-encryption-recovery control surfaces do not apply, and data-loss-prevention (DLP) and exfiltration-detection control surfaces become the principal pre-extortion intervention layer.
Targeting profile
OAK-G18's victim profile is enterprise-IT-and-mid-market-targeted, with sector concentration mirroring the broader Conti-successor cohort but with a stated preference for victims where encryption-deployment would be operationally disadvantageous:
- Mid-market enterprise across all sectors — Karakurt's victim profile in the CISA AA22-152A advisory and subsequent industry-forensic tracking is dominated by mid-market enterprise targets across U.S. and European geographies; sector distribution is more uniform than the Conti-headline-target profile of healthcare-and-government concentration, reflecting the data-extortion-only operating-model's lower per-incident profile.
- Healthcare and adjacent sensitive-data sectors — present in the Karakurt victim cohort but with proportionally lower frequency than in the Conti / Black Basta cohort, consistent with the encryption-free operating-model that depends on data-disclosure-threat-magnitude rather than operational-disruption-magnitude as the primary leverage surface.
- Cryptocurrency-industry firms as occasional targets — present but not the dominant target class; G18 is enterprise-extortion-led, not crypto-native-extraction-led.
- Downstream cryptocurrency users — only as secondary victims of the laundering rails the operation depends on.
Observed Techniques
OAK v0.1's Tactic catalog is on-chain-extraction-focused; Karakurt's intrusion surface (off-chain phishing / malware-loader chains, Cobalt Strike post-exploitation, credential theft via Mimikatz, lateral movement via RDP / SMB, and data-exfiltration via rclone / Mega.io / Filezilla / FreeFileSync) sits outside that scope. The on-chain Techniques observed in OAK-G18-attributable activity are concentrated on the payment-and-laundering side:
- OAK-T7.001 (Mixer-Routed Hop) — observed as the dominant Karakurt-affiliate ransom-laundering route 2021–2023 with Sinbad pre-takedown the principal venue per Chainalysis tracking; post-Sinbad-takedown rotation onto smaller mixer infrastructure observed; declined materially across 2023–2024 in step with the sector-wide post-Tornado-Cash-designation decline.
- OAK-T7.002 (CEX Deposit-Address Layering) — the canonical post-2023 Karakurt off-ramp, with affiliate-controlled deposit-address activity at non-KYC, lax-KYC, and Russian-speaking commercial-criminal off-ramp venues a recurring industry-forensic signature; the cluster's downstream-laundering profile shows substantial overlap with OAK-G03 Russian laundering infrastructure per Chainalysis and TRM Labs aggregate tracking.
- OAK-T7.003 (Cross-Asset / Cross-Chain Laundering) — observed in Karakurt laundering chains, with Bitcoin-to-stablecoin and Bitcoin-to-Monero conversion legs documented per industry-forensic write-ups.
- OAK-T8.001 (Common-Funder Cluster Reuse) — the attribution-side Technique used by Mandiant, Microsoft, Chainalysis, TRM Labs, and CrowdStrike to maintain Conti-to-Karakurt operator-cohort-continuity attribution. Karakurt affiliate wallet clusters share funder addresses with documented Conti-era and Black Basta affiliate clusters, supporting the Conti-cohort-continuity attribution.
- OAK-T8.002 (Cross-Chain Operator Continuity) — observed across the Conti-to-Karakurt cohort transition and across post-2022 affiliate-cohort rotations.
- Adjacent / pre-incident vectors not in OAK v0.1 scope: off-chain initial access via phishing-and-malware-loader chains (historically TrickBot / IcedID / BazarLoader / Cobalt Strike, with post-Operation-Endgame loader rotation), Cobalt Strike post-exploitation, Mimikatz / domain-admin credential theft, RDP / SMB lateral movement, and data-exfiltration via rclone / Mega.io / Filezilla / FreeFileSync. These are documented in CISA AA22-152A and are the canonical Karakurt intrusion vectors.
- Operating-model-novelty marker not in OAK v0.1 scope: the prototype status of Karakurt as the first publicly-documented sustained data-extortion-only operating model in the ransomware-and-data-extortion ecosystem is itself a defender-relevant marker. The data-extortion-only operating model has subsequently spread to OAK-G14 Cl0p (mid-2023 pivot), BianLian, RansomHouse, and adjacent clusters; G18 is the historical anchor for the model.
Observed Examples
No public incidents at v0.1 — worked examples pending per-incident forensic publication.
OAK v0.1 does not yet contain a worked example whose primary axis is a Karakurt-attributed direct-cryptocurrency-firm intrusion; the on-chain angle of G18 is the laundering of data-extortion payments rather than direct crypto-firm intrusion. The high-salience public-record events anchoring the cluster:
- CISA / FBI / Treasury / FinCEN AA22-152A "Karakurt Data Extortion Group" advisory (June 1, 2022). Joint cyber-security advisory characterising Karakurt TTPs across the 2021–2022 operating window, the data-extortion-only operating-model signature, and the Conti-cohort-continuity attribution at the operator-cohort level (
[cisaaa22152a]). Attribution at confirmed. The advisory was updated in March 2023 to extend the Karakurt-cohort tracking through 2023. - Karakurt-Conti operator-cohort-continuity evidence (mid-2021 onward). Per Mandiant, Microsoft, and CrowdStrike cross-vendor reporting, Karakurt operator personnel substantively overlap with Conti / Wizard Spider cohort personnel at the internal-chat-recovered level; the attribution is confirmed at the cohort level, inferred-strong at the named-individual level.
- Karakurt ChipMixer pre-takedown laundering chain. Per Chainalysis tracking, Karakurt-affiliate proceeds were laundered through ChipMixer prior to the March 2023 ChipMixer takedown; the post-takedown laundering rotation followed the broader Conti-successor-cohort migration onto Sinbad and adjacent venues.
- Tetra Defense and Infinitum I.T. mid-2022 incident reports. Industry-forensic reporting on Karakurt-attributed intrusions during the cluster's peak operating window in 2022, characterising the recovery-and-negotiation behaviour profile and the data-exfiltration-via-commodity-tooling tradecraft.
- Operating-model-prototype signal. Karakurt's mid-2021 emergence pre-dates OAK-G14 Cl0p's mid-2023 data-extortion-only pivot by approximately two years and pre-dates the BianLian / RansomHouse data-extortion-only emergence as well; G18 is the canonical operating-model-prototype in the public record for the data-extortion-only ransomware-extortion model.
- Worked examples for specific G18-mediated extortion-payment laundering flows are pending v0.x and will live under
examples/once the per-incident attribution surface stabilises sufficiently for the OAK confirmed / inferred-strong distinction.
Citations
[cisaaa22152a]— CISA / FBI / Treasury / FinCEN joint cyber-security advisory AA22-152A "Karakurt Data Extortion Group," June 1, 2022, with March 2023 update.[cisaaa22046a]— CISA / FBI / Secret Service joint advisory AA22-046A on Conti ransomware (referenced for the Conti-cohort-substrate framing).[contileaks2022]— ContiLeaks insider-disclosure corpus, late February 2022 (referenced for the Conti-cohort-continuity framing).[mandiantcontileaks2022]— Mandiant analysis of the ContiLeaks corpus and Conti's organisational structure (referenced for the Conti-cohort-continuity framing).[crowdstrikewizardspider2022]— CrowdStrike Wizard Spider operator-cohort tracking through the Conti dissolution and successor-brand dispersal (referenced for the Karakurt-as-Conti-side-channel framing).[chainalysis2025ransomware]— Chainalysis 2024-recap ransomware report; documents Karakurt aggregate proceeds and the data-extortion-only operating-model evolution.[chainalysis2022conti]— Chainalysis Conti-attributable ransom-payment-volume tracking (referenced for the cross-cohort wallet-cluster-continuity framing).[ofac2022garantex]— Treasury OFAC Garantex designation (referenced for the OAK-G03 downstream-laundering-venue context).[ofac2022tornado]— sector-wide mixer-laundering enforcement context (referenced for the post-2022 ransomware-mixer-share decline, not for shared cluster identity).
Discussion
On the attribution-strength split. The Karakurt operator-cluster attribution is confirmed at the CISA-advisory layer — the June 2022 CISA / FBI / Treasury / FinCEN AA22-152A advisory and the March 2023 update produce a confirmed-grade public-attribution surface. Attribution that specific affiliate operators are tied to specific real-world identities is inferred-strong per Mandiant / Microsoft / CrowdStrike cross-cohort tracking. Attribution that the Karakurt cohort overlaps at the personnel level with the Conti / Wizard Spider cohort is confirmed at the cohort level (per CISA AA22-152A and the broader Conti-cohort-continuity industry consensus) and inferred-strong at the named-individual level. OAK contributors writing G18-attributed examples should preserve this attribution-strength split per-incident.
On why OAK-G18 is operating-brand cluster rather than Conti / Wizard Spider operator-cohort. Naming this Group entry "Wizard Spider" or "Conti / Wizard Spider successor" would have framed the cluster at the broader operator-cohort level, but would mis-frame the operating-brand-persistence pattern that the post-Conti dispersal made the dominant 2022–2025 ransomware-sector pattern. The Karakurt-branded data-extortion operation is one of the principal direct-successor brands within the broader Conti-cohort dispersal (alongside OAK-G11 Black Basta, OAK-G17 BlackByte, and the Royal / BlackSuit cohort), and the Karakurt-branded operating-model continuity from mid-2021 through 2025 is the cleaner persistent identity than the broader Wizard-Spider-cohort substrate. By the same logic, naming the Group at the individual-affiliate level would mis-frame the operating-brand-persistence pattern that defines the cluster.
On the cluster-boundary distinction with OAK-G11 Black Basta, OAK-G16 Akira, OAK-G17 BlackByte (Conti-successor encryption-and-data-extortion cohort). All four clusters share Conti / Wizard Spider operator-cohort substrate, share Russian-language operator personnel, and share the broader Conti-successor-affiliate-diaspora wallet-cluster-continuity attribution surface. They differ along the operating-model axis (G18 is encryption-free data-extortion-only; G11 / G16 / G17 retain encryption-and-data-extortion double-extortion), the intrusion-side tradecraft axis (G11 / G16 / G17 deploy ESXi-targeted Linux variants for hypervisor-level encryption, while G18 has no encryption-deployment phase), and the attribution-surface axis (G18 is confirmed-by-CISA-advisory plus FinCEN-coordinated; G11 is confirmed-by-CISA-AA24-131A; G16 is confirmed-by-CISA-AA24-109A; G17 is confirmed-by-CISA-TA22-039A). Defenders running anti-G18 control sets should expect substantial overlap with anti-G11 / G16 / G17 control-set design at the off-chain-laundering-and-ransom-payment-flow layer (Russian-speaking commercial-criminal off-ramp profile) but should expect distinct intervention-layer requirements: anti-G18 control sets concentrate on data-loss-prevention (DLP) and exfiltration-detection rather than encryption-detection-and-encryption-recovery.
On the cluster-boundary distinction with OAK-G14 Cl0p (the operating-model parallel). G18 (Karakurt) and G14 (Cl0p, post-mid-2023) both operate data-extortion-only operating models and are the two principal sustained-data-extortion-only clusters in the public record. They differ along the operator-cohort-substrate axis (G18 is Conti / Wizard Spider cohort-derived; G14 is TA505 / FIN11 cohort-derived), the intrusion-side tradecraft axis (G18 is conventional phishing-and-malware-loader-chains-led; G14 is mass-exploitation-of-MFT-products-led), the operating-model-emergence axis (G18 was born data-extortion-only in 2021; G14 pivoted to data-extortion-only in 2023 from a prior encryption-and-data-extortion model), and the victim-cohort axis (G18 is mid-market-enterprise-distributed; G14 is mass-exploitation-cohort-driven with multi-thousand-organisation campaigns). Cl0p's mid-2023 pivot adopted variants of the Karakurt operating-model template; G18 is the historical anchor for the model.
On the operating-model-prototype framing. Karakurt's mid-2021 emergence pre-dates the broader spread of the data-extortion-only operating model in the ransomware-and-data-extortion ecosystem. The pattern subsequently spread to BianLian (early 2022 emergence as encryption-and-data-extortion, pivoted to data-extortion-only late 2022), RansomHouse (data-extortion-only since inception in late 2021 but operating at smaller scale), the OAK-G14 Cl0p mid-2023 pivot (the highest-volume case of the model), and adjacent clusters. The defender takeaway is that data-extortion-only is a sustained operating-model variant in the ransomware-extortion ecosystem rather than an isolated operator choice, and counter-party-screening control sets need to assume that data-disclosure-threat-only-extortion is part of the threat-actor toolkit. OAK should not absorb operating-model-novelty into its on-chain Tactic catalog at v0.1 — it would dilute the on-chain framing — but G18's documentation should preserve the marker for downstream consumers building incident-response runbooks.
On the relationship to OAK-G03 Russian laundering infrastructure. G03 (Russian laundering infrastructure, Garantex / Grinex / A7A5 lineage) was a documented downstream venue for some fraction of Karakurt proceeds, with the G18 / G03 chain showing substantial overlap per Chainalysis and TRM Labs aggregate tracking. The cluster's Russian-speaking commercial-criminal off-ramp profile shows distribution across multiple non-KYC and lax-KYC venues with concentration at OAK-G03-cluster venues during the 2022–2024 window. Defenders running OAK-G03 watchlists should expect substantial overlap with G18-attributed inflows.
On v0.x evolution. G18's 2026+ trajectory will depend on (a) whether further CISA / FBI advisory tempo or FinCEN-coordinated enforcement extends the post-AA22-152A pressure surface; (b) whether the cluster continues operating through the post-Conti-dispersal-cohort-evolution window or whether it dissolves and migrates into successor brands; (c) whether the data-extortion-only operating model continues spreading across the broader ransomware-extortion ecosystem (which would extend G18's historical-prototype significance); and (d) whether a worked example of Karakurt-mediated extortion-payment laundering is added under examples/ once the per-flow attribution surface stabilises sufficiently. OAK should update this entry as the public record evolves; the attribution-strength conventions documented here apply to all such updates. Future OAK Group additions in the data-extortion-only sector — BianLian and RansomHouse as standalone successor-brand entries — would each warrant their own OAK-Gnn entry rather than extension of G18, on the same per-cluster identity principle.