Full Report
The French-speaking gang managed to carry out over 30 successful attacks on banks, financial services and telecommunications companies, mainly located in Africa.
Analysis Summary
# Threat Actor: OPERA1ER
## Attribution & Identity
* **Name:** OPERA1ER
* **Aliases:** Common-Raven (associated by other vendors), "NXSMS" (referenced in full report contexts)
* **Identity:** A French-speaking cybercriminal group.
* **Associations:** Linked to organized financial crime; known for using "off-the-shelf" tools rather than custom-developed exploits.
## Activity Summary
The group has conducted over 30 successful attacks against financial institutions and telecommunications providers. Their operations are characterized by high levels of persistence and a methodical approach to compromising internal banking systems. Recent investigations by Group-IB identified a specific infrastructure cluster used by the actor to facilitate these thefts, which have resulted in the loss of millions of dollars.
## Tactics, Techniques & Procedures
* **Initial Access:** Highly targeted phishing/spear-phishing (implied by infrastructure naming conventions like `banqueislamik`).
* **Lateral Movement & Persistence:** Extensive use of Cobalt Strike Beacons.
* **Command and Control (C2):** Utilization of Cobalt Strike listeners, specifically on non-standard ports (e.g., port 777).
* **Defense Evasion:** Use of VPN infrastructure and DynDNS services to mask the origin of their traffic.
* **Techniques (MITRE ATT&CK):**
* **T1583.003:** Acquire Infrastructure: DNS Server (Use of DynDNS)
* **T1584.005:** Compromise Infrastructure: Botnet (Use of BitRAT)
* **T1071.001:** Application Layer Protocol: Web Protocols (Standard C2 traffic)
* **T1573:** Encrypted Channel (SSH and VPN usage)
* **T1021.004:** Remote Services: SSH
## Targeting
* **Sectors:** Banks, Financial Services, and Telecommunications.
* **Geography:** Primarily located in Africa (French-speaking regions).
* **Victims:** Over 30 successful attacks; specific domains suggest targeting of Islamic banking institutions (`banqueislamik`).
## Tools & Infrastructure
* **Malware Families:**
* BitRAT
* Cobalt Strike (Beacons)
* **Infrastructure:**
* **C2 Domains:**
* `files[.]ddrive[.]online`
* `banqueislamik[.]ddrive[.]online`
* **IP Addresses:**
* `20[.]91[.]192[.]253`
* `188[.]126[.]90[.]14`
* `178[.]73[.]192[.]17`
* `46[.]246[.]84[.]17`
* `46[.]246[.]84[.]21`
* `43[.]205[.]33[.]202`
* `46[.]246[.]84[.]74`
* `72[.]11[.]142[.]240`
* **VPN Services:** FrootVPN
* **SSH Fingerprints:**
* `657a78dcd2c190f00b2f4ef745dd2cdd`
* `e0c528d70679c1c9118c7d3d44cc5b69`
## Implications
OPERA1ER represents a significant threat to the African financial sector. Their ability to successfully exfiltrate millions using commodity "off-the-shelf" tools demonstrates that sophisticated custom malware is not a prerequisite for high-impact financial theft. Their operations are patient and focused on the long-term compromise of banking internals rather than quick "smash-and-grab" attacks.
## Mitigations
* **Network Monitoring:** Implement hunting rules for the identified SSH fingerprints and monitor for unusual traffic on port 777.
* **Domain Filtering:** Block access to DynDNS provider domains and the specific `ddrive[.]online` subdomains identified.
* **Endpoint Security:** Deploy EDR solutions capable of detecting Cobalt Strike Beacon memory signatures and BitRAT execution.
* **VPN Awareness:** Monitor for connections to known commercial VPN providers like FrootVPN from within sensitive corporate network segments.