Cymulate named a Customers' Choice in 2026 Gartner® Peer Insights™
Learn More
New: Cymulate Cowork for Agentic Cyber Defense Engineering
Learn More
New Bitsight Integration: Turn Threat Intelligence into Validated Security
Learn More
Introducing Cymulate Vero AI for Agentic Cyber Defense Engineering
Learn More

Bluebottle Attacks The Financial Sector In Africa

January 10, 2023

The Bluebottle threat group, also known as Common Raven and OPERA1ER, targeted the financial sector in French speaking countries in Africa with a range of dual-use tools, commodity malware, and living-of-the-land utilities. The various tools and malicious software were used for discovery, network tunneling, persistence, and defense evasion. The Netwire and Quasar RATs along with Cobalt Strike, GuLoader, Mimikatz, and multiple Microsoft Windows command-line utilities were used to carry out the operation.