A threat group named OPERA1ER has been linked to a series of more than 30 successful cyber-attacks aimed at banks, financial services, and telecom companies across Africa, Asia, and Latin America between 2018 and 2022.
According to the analysts at Singapore-based cybersecurity company Group-IB, the attacks have led to thefts totaling $11 million, with actual damages estimated to be as high as $30 million.
OPERA1ER, also called by the names DESKTOP-GROUP, Common Raven, and NXSMS, is believed to be active since 2016, operating with the aim of conducting financially motivated heists and exfiltration of documents for further use in spear-phishing attacks.
The analysts have been tracking OPERA1ER since 2019 and noticed that the group changed its techniques, tactics, and procedures (TTPs) last year.
The hacker group is formed of French-speaking members believed to operate from Africa. Apart from targeting companies in Africa, the gang also hit organizations in Argentina, Paraguay, and Bangladesh.
They often operate during weekends and public holidays and their entire arsenal is based on open-source programs and trojans, or free published RATs that can be found on the dark web.
This includes off-the-shelf malware such as Nanocore, Netwire, Agent Teslam Venom RAT, BitRAT, Metasploit, and Cobalt Strike Beacon, among others.
The hackers obtain initial access through high-quality spear-phishing emails with invoice and delivery-themed lures written primarily in French and to a lesser extent in English.
These messages feature ZIP archive attachments or links to Google Drive, Discord servers, infected legitimate websites, and other actor-controlled domains, which lead to the deployment of remote access trojans.
Using stolen credentials, OPERA1ER accesses email accounts and performs lateral phishing, studies internal documentation to understand money transfer procedures and protection mechanisms, and carefully plans the final, cashing out step.
Typically, the hackers targeted operator accounts that controlled large amounts of money and used stolen credentials to transfer the funds into Channel User accounts, eventually moving them into subscriber accounts under their control.
Usually, the cashing out event took place on a holiday or over the weekend to minimize the chances of the compromised organizations responding to the situation in time.
These findings were carried out in collaboration with telecom giant Orange. The company noted that there are no zero-day threats in OPERA1ER’s arsenal, and the attacks often use exploits for vulnerabilities discovered three years ago.














Comments