Uptime Hamster: 10d 6h 2mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza BlueBottle

BlueBottle

0 incidentes 0 paises 0 sectores apt Unknown Ultimo: -
Aliases: OPERA1ER, DESKTOP-GROUP o NXSMS, orientado a objetivos específicos
Ver en IntelTracker → APTTrail →
BlueBottle is a financially motivated cybercrime group known by multiple aliases including OPERA1ER, DESKTOP-GROUP, Common Raven, and NXSMS. The group was first observed in 2016 and primarily targets the financial sector, such as banks in French-speaking African nations and other countries globally, with the clear motivation of direct financial gain. BlueBottle differentiates itself through its consistent reliance on living off the land techniques, dual-use tools, and commodity malware rather than custom-developed solutions, while actively adapting its tactics to bypass security products and maintain long-term persistence within victim networks.

Aliases del actor

OPERA1ERDESKTOP-GROUP o NXSMSorientado a objetivos específicos

Actores similares

silentransomgroupactor · 36GroupIB_TIactor · 11bonacigroupransomware · 2thegreenbloodgroupransomware · 2vanirgroupransomware · 2SilentRansomGroupactor · 2the-green-blood-groupactor · 2apt-equationgroupactor · 1apt-group5actor · 1bluewindgroupactor · 1
Tecnicas MITRE
T1078, T1071.001, T1059.003, T1566.001
Tipo
apt
Pais origen
Unknown
Motivacion
-
Impacto
6
Actualizado
Wed, 08 No

Sectores objetivo (SOCRadar)

FinanceTelecommunicationsBanking