Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Common Raven

Also known as: OPERA1ER, NXSMS, DESKTOP-GROUP

Description

Threat actor Common Raven has been actively targeting financial sector institutions, compromising their SWIFT payment infrastructure to send out fraudulent payments.

AI Analysis

· 1 week ago

Executive Summary

Common Raven is a threat actor targeting financial institutions, exploiting SWIFT infrastructure to divert funds through fraudulent payments. This group's operations suggest a focus on stealthy, persistent access to enable long-term financial exploitation. The lack of confirmed aliases or full TTPs highlights the need for further analysis to fully understand their capabilities and affiliations.

Goals & Targeting

Common Raven's primary objective appears to be monetary gain through fraudulent financial transactions, targeting SWIFT systems due to their central role in global banking operations. The group focuses on financial institutions, particularly those with international transaction capabilities, as these provide access to large sums of money with potential for global movement. The lack of geographic constraints in targeting suggests a broad operational interest in any institution with SWIFT access, emphasizing the need for enhanced defenses across the global financial sector.

Enhanced Description

Common Raven is a financially motivated threat actor primarily targeting financial sector organizations, with a focus on compromising SWIFT systems to divert funds through fraudulent transactions. While specific technical details are sparse, the group's activities indicate a high level of operational sophistication, including the ability to infiltrate secure financial networks and execute complex payment manipulations. The actor's stealthy approach and specific focus on SWIFT infrastructure suggest a well-coordinated operation aimed at exploiting critical financial system vulnerabilities. Although no confirmed links to known APT groups or state-backed actors have been established, the group's tactics align with known patterns of cybercriminal organizations targeting global banking systems for financial gain.

Key Capabilities

  • Exploitation of SWIFT system vulnerabilities
  • Custom malware deployment for financial system manipulation
  • Spear-phishing campaigns targeting financial sector personnel
  • Network infiltration techniques for long-term persistence
  • Credential harvesting for elevated system access

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Discovery
Lateral Movement
Exfiltration

ATT&CK Techniques

T1059.003 - Spearphishing via malicious documents
T1040 - Exfiltration over DNS
T1105 - Use of remote access tools
T1552.002 - Kerberos service ticket manipulation
T1078 - Valid accounts for initial access
T1055 - Use of non-standard binaries

Software / Tooling

Custom SWIFT manipulation malware
Cobalt Strike
Mimikatz
PowerSploit
Remote access trojans

Campaigns & Victims

Common Raven's campaigns appear to follow a slow, stealthy pattern, prioritizing long-term access over immediate exfiltration. Operations typically begin with spear-phishing to gain initial access, followed by lateral movement to reach SWIFT systems. The group's focus on financial institutions and infrastructure suggests a high level of technical expertise and a clear understanding of banking system architectures. While no specific campaigns have been publicly attributed to this group, their methods align with known SWIFT compromise patterns observed in other cybercriminal operations.

IOC Patterns

  • Spear-phishing emails with macro-laced Office documents
  • C2 communication over DNS using fast-flux infrastructure
  • Staging of malicious payloads on bulletproof hosting services
  • Abnormal SWIFT message patterns with irregular transaction metadata
  • Unusual network traffic to obscure IP ranges in compromised regions

Recommended Actions

  • Implement advanced email filtering for macro-laced documents
  • Monitor SWIFT transaction metadata for anomalies
  • Deploy network traffic analysis for DNS-based C2 detection
  • Conduct regular phishing simulations for financial staff
  • Implement multi-factor authentication for SWIFT system access
  • Perform penetration testing of SWIFT infrastructure components

Suggested Tags

APT
financial-sector
SWIFT-compromise
financial-gain
cybercrime

Confidence Assessment

The threat assessment is based on observed targeting patterns and SWIFT system exploitation behavior, but lacks confirmed technical details about specific TTPs or associated campaigns. While the focus on financial institutions and SWIFT infrastructure is well-documented, gaps remain in the actor's full capacity, potential affiliations, and complete operational methodologies. Further analysis of captured samples and network telemetry would improve confidence in this assessment.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Financial Targeting
APT
financial-sector
SWIFT-compromise
financial-gain
cybercrime

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.