Also known as: OPERA1ER, NXSMS, DESKTOP-GROUP
Threat actor Common Raven has been actively targeting financial sector institutions, compromising their SWIFT payment infrastructure to send out fraudulent payments.
Executive Summary
Common Raven is a threat actor targeting financial institutions, exploiting SWIFT infrastructure to divert funds through fraudulent payments. This group's operations suggest a focus on stealthy, persistent access to enable long-term financial exploitation. The lack of confirmed aliases or full TTPs highlights the need for further analysis to fully understand their capabilities and affiliations.
Goals & Targeting
Common Raven's primary objective appears to be monetary gain through fraudulent financial transactions, targeting SWIFT systems due to their central role in global banking operations. The group focuses on financial institutions, particularly those with international transaction capabilities, as these provide access to large sums of money with potential for global movement. The lack of geographic constraints in targeting suggests a broad operational interest in any institution with SWIFT access, emphasizing the need for enhanced defenses across the global financial sector.
Enhanced Description
Common Raven is a financially motivated threat actor primarily targeting financial sector organizations, with a focus on compromising SWIFT systems to divert funds through fraudulent transactions. While specific technical details are sparse, the group's activities indicate a high level of operational sophistication, including the ability to infiltrate secure financial networks and execute complex payment manipulations. The actor's stealthy approach and specific focus on SWIFT infrastructure suggest a well-coordinated operation aimed at exploiting critical financial system vulnerabilities. Although no confirmed links to known APT groups or state-backed actors have been established, the group's tactics align with known patterns of cybercriminal organizations targeting global banking systems for financial gain.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Common Raven's campaigns appear to follow a slow, stealthy pattern, prioritizing long-term access over immediate exfiltration. Operations typically begin with spear-phishing to gain initial access, followed by lateral movement to reach SWIFT systems. The group's focus on financial institutions and infrastructure suggests a high level of technical expertise and a clear understanding of banking system architectures. While no specific campaigns have been publicly attributed to this group, their methods align with known SWIFT compromise patterns observed in other cybercriminal operations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The threat assessment is based on observed targeting patterns and SWIFT system exploitation behavior, but lacks confirmed technical details about specific TTPs or associated campaigns. While the focus on financial institutions and SWIFT infrastructure is well-documented, gaps remain in the actor's full capacity, potential affiliations, and complete operational methodologies. Further analysis of captured samples and network telemetry would improve confidence in this assessment.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics