SYMBOLCOMMON_NAMEaka. SYNONYMS

Common Raven  (Back to overview)

aka: DESKTOP-GROUP, NXSMS, OPERA1ER

Threat actor Common Raven has been actively targeting financial sector institutions, compromising their SWIFT payment infrastructure to send out fraudulent payments.


Associated Families

There are currently no families associated with this actor.


References
2022-11-03Group-IBRustam Mirkasymov
Financially motivated, dangerously activated: OPERA1ER APT in Africa
Cobalt Strike Common Raven
2021-01-01SWIFTSWIFT
SWIFT Report on COMMON Raven
Common Raven
2020-11-19Rewterz Information SecurityRewterz Information Security
Rewterz Threat Alert – Common Raven – IOCs
BatchWiper Common Raven

Credits: MISP Project