Common Raven

Aliases: OPERA1ER, NXSMS, DESKTOP-GROUP

Primary motivation
financial-gain
Sophistication
advanced
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:00:46

Targeted industries: financial-services

Context

Threat actor Common Raven has been actively targeting financial sector institutions, compromising their SWIFT payment infrastructure to send out fraudulent payments.

Reports & references

  • rewterz.com — Rewterz Threat Alert Common Raven Iocs (report)
  • www2.swift.com — 10118 (report)
  • blog.group-ib.com — Opera1Er Apt (report)

External references