A threat actor that researchers are calling OPERA1ER has stolen at least $11 million from banks and telecommunications service providers in Africa using off-the-shelf hacking tools.

From 2018 to 2022, hackers carried out more than 35 attacks – with almost a third taking place last year.
See also: RomCom RAT operators exploit well-known software to distribute malware
The Group-IB team of analysts, in collaboration with Orange's CERT-CC department, has been monitoring the OPERA1ER group since 2019. They observed that the group changed its techniques, tactics and procedures (TTPs) last year.
Concerned about losing track of the threat actor, the cybersecurity firm waited for the group to resurface before publishing an updated report. This year, Group-IB noticed that the hackers were active once again.

Details of OPERA1ER attacks
The hacking group, which is made up primarily of French-speakers originating from Africa, is known to target companies outside the continent, such as in Argentina, Paraguay and Bangladesh.
To penetrate corporate servers, the OPERA1ER group uses open source tools, malware, and frameworks such as Metasploit and Cobalt Strike.
They initially gain access to people's accounts through spear-phishing emails that discuss popular topics, such as invoices or postal delivery notifications.
The emails have attachments that deliver the first-stage malware, including Netwire, bitrat, venomRAT, AgentTesla, Remcos, Neutrino, BlackNET, and Venom RAT.
Researchers found that the OPERA1ER group can remain inside a compromised network for 3-12 months and sometimes returns to attack the same company again.
See also: New Crimson Kingsnake group impersonates law firms in BEC attacks
Researchers say that once they gain access to a victim's network, hackers can also use the infrastructure as a launching pad for other targets.
Group-IB says the threat actor creates “high-quality” spear-phishing emails written in French. Most often, the messages impersonate either the government tax office or a recruitment agent from the Central Bank of West African States (BCEAO).

The OPERA1ER group steals credentials to gain access to email accounts, then performs lateral phishing, studies internal documentation to understand money transfer and protection mechanisms, and carefully designs the final redemption step.
See also: LockBit ransomware: Gang threatens to leak Continental data
Typically, hackers targeted operator accounts that controlled large sums of money and used stolen credentials to transfer the funds to user accounts , ultimately transferring them to subscriber under their control.

In its report today, Group-IB explains that gang members “cash out” the cash through a network of ATMs.
To reduce the likelihood of detection, these redemption events typically occurred on holidays or during the weekend.
Unlike other scams that steal money from banks, OPERA1ER specifically targeted the messaging interface software SWIFT in order to obtain details about anti-fraud systems and bypass.
Group-IB published a 75-page technical report, detailing all indicators of compromise (IoCs) and information about the attacks attributed to OPERA1ER.
Information source: bleepingcomputer.com
