logo

Financially motivated, dangerously activated: OPERA1ER APT in Africa

ID: 18788322-ac60-5456-9e7b-7d3869a4e164

STIX ID: report--18788322-ac60-5456-9e7b-7d3869a4e164

Feed Name: Group-IB Blog

Threat Score
78/100

Date Published: 2022-11-03

Date Updated: 2026-04-27

...
...

**OPERA1ER: Playing God without permission** — Group-IB and Orange describe a French-speaking criminal APT (aka DESKTOP-GROUP/Common Raven/NXSMS) responsible for 30+ targeted attacks on African banks, financial services, and telecoms from 2018–2022, with confirmed thefts of at least $11M; the report maps TTPs (Cobalt Strike, BitRAT, VPN/DynDNS), publishes new Cobalt Strike servers and fingerprints, and supplies IOCs and hunting heuristics for tracking their infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.