Common_Raven__2022__Group-IB_RPRT_OPERA1ER_EN_full.pdf
ID: 7509c1ac-ad17-4fc1-9400-d4689068a214
STIX ID: report--7509c1ac-ad17-4fc1-9400-d4689068a214
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2022-10-18
Last Modified Date: 2022-10-18
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Group-IB / Orange-CERT report documents OPERA1ER, a financially motivated, French-speaking cybercrime group that conducted at least 30 targeted campaigns since 2019 against banks, payment gateways and mobile money platforms across Africa and beyond; the actors used spear-phishing to deliver off‑the‑shelf RATs and red-team frameworks (Cobalt Strike, Metasploit), performed long dwell reconnaissance, credential harvesting and privilege escalation to access back-end and SWIFT interfaces, and orchestrated large ATM/mule cashouts — the report includes a full kill chain, detailed TTPs, IoCs (domains, IPs, file hashes, SMTP headers, ngrok tokens) and mitigation/hunting guidance.
