Law enforcement has detained a suspect believed to be a key member of the OPERA1ER cybercrime group, that has targeted mobile banking services and financial institutions in malware, phishing, and Business Email Compromise (BEC) campaigns.
The gang, also known as NX$M$, DESKTOP Group, and Common Raven, is suspected to have stolen between $11 million and $30 million over the last four years in more than 30 attacks spanning 15 countries across Africa, Asia, and Latin America.
The suspect was arrested in Côte d’Ivoire in early June in a joint law enforcement action named Operation Nervone with the help of AFRIPOL, Interpol’s Cybercrime Directorate, cybersecurity company Group-IB, and telecom carrier Orange.
Group-IB analysts and the CERT-CC department at Orange, have been tracking the OPERA1ER group since 2019. They hacker gang have been linked to over 35 successful attacks between 2018 and 2022.
OPERA1ER members predominantly speak French and are believed to operate from Africa, and they rely on various tools in their attacks, including open-source solutions, common malware, and frameworks like Metasploit and Cobalt Strike.
However, initial access to targets’ networks is gained through spear-phishing emails that exploit popular subjects such as invoices or postal delivery notifications and push a wide range of first-stage malware, including Netwire, BitRAT, venomRAT, AgentTesla, Remcos, Neutrino, BlackNET, and Venom RAT, as well as password sniffers and dumpers.
OPERA1ER has been observed maintaining access to compromised networks for a period ranging from three to twelve months, occasionally targeting the same company multiple times.
They also typically focus on operator accounts that control significant sums of money, using stolen credentials to transfer funds into Channel User accounts before redirecting them to subscriber accounts under their control. The group withdraws the stolen money as cash through an extensive network of ATMs over holidays or weekends to avoid detection.














Comments