OPERA1ER, also known as DESKTOP-GROUP, Common Raven, and NXSMS, is a French-speaking, financially motivated cybercriminal group whose activity has been traced to 2016. It primarily targets African banks, financial services providers, mobile banking services, and telecommunications companies, with additional victims in Asia and South America. At least 30 successful attacks were identified during 2019–2021, affecting at least 15 distinct organizations and resulting in at least $11 million in confirmed theft. Some victims were compromised repeatedly. The group gains initial access through tailored French- and English-language spear phishing using malicious attachments and download links. It relies on publicly available tools and commercial or open-source malware rather than a unique malware arsenal. Its tools include NanoCore, H-Worm, Remcos, Adwind, Agent Tesla, NetWire, BitRAT, Venom RAT, Metasploit, and Cobalt Strike. Post-compromise operations include Active Directory reconnaissance, network scanning, credential harvesting, keylogging, password spraying, privilege escalation, and lateral movement through RDP, PsExec, PowerShell Remoting, WinRM, and SMB Beacons. It has exploited known vulnerabilities, including EternalBlue and CVE-2019-1405 and CVE-2019-1322. Persistence mechanisms include scheduled tasks, registry autoruns, privileged accounts, AnyDesk, and tunneled RDP access. Defense evasion includes antivirus removal, executable masquerading, payload packing, and process injection. The group also exfiltrates internal documentation to support subsequent spear-phishing operations. OPERA1ER commonly maintains access for three to twelve months before cashing out, frequently acting during weekends and public holidays. It targets payment gateways and internet banking systems, harvesting credentials for transaction initiation and multiple approval roles to bypass segregation-of-duties controls. Funds are transferred through attacker-controlled accounts and mule networks, followed by coordinated ATM withdrawals. Operations have used bulk transaction APIs, automated USSD transfers, and hundreds of mule accounts. The group has also accessed SWIFT messaging interfaces and repurposed compromised infrastructure as staging and pivot points for attacks against other organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
30 malware families attributed to this actor across reporting.
25 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
OPERA1ER executed Invoke-EternalBlue command via Cobalt Strike framework. This command utilizes security issues patched by MS17-010 ... in 2021 these exploits are still relevant and the operator uses that way commonly.
COMahawk exploits were also used ... exploits two vulnerabilities (CVE-2019-1405 and CVE-2019-1322) in UPnP to execute a command as an elevated user.
COMahawk exploits were also used ... exploits two vulnerabilities (CVE-2019-1405 and CVE-2019-1322) in UPnP to execute a command as an elevated user.
308 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as one of several threat actors known to use VenomRAT and AsyncRAT.
French-speaking, financially motivated cybercrime group targeting banks, financial services, mobile banking providers, and telecommunications companies, predominantly in Africa. The report attributes at least 30 attacks during 2019–2021 to the group, with $11 million in confirmed theft and estimated losses exceeding $30 million. Operators use publicly available malware and penetration-testing tools to compromise networks, obtain domain administrator privileges, steal payment-platform credentials, and conduct fraudulent transfers followed by coordinated ATM cash-outs through mule networks. They accessed SWIFT messaging interfaces in at least two banks, although theft through SWIFT is assessed with only moderate confidence. Intrusions can precede cash-outs by 3–12 months, and some victims were compromised repeatedly. The report identifies an African operational base but does not establish a specific country of origin or state sponsorship.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.