Common Raven
Aliases: OPERA1ER, NXSMS, DESKTOP-GROUP
- Primary motivation
- financial-gain
- Sophistication
- advanced
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:00:46
Targeted industries: financial-services
Context
Threat actor Common Raven has been actively targeting financial sector institutions, compromising their SWIFT payment infrastructure to send out fraudulent payments.
Reports & references
- rewterz.com — Rewterz Threat Alert Common Raven Iocs (report)
- www2.swift.com — 10118 (report)
- blog.group-ib.com — Opera1Er Apt (report)