NARWHAL SPIDER

Aliases: GOLD ESSEX, TA544, Storm-0302, NARWHAL SPIDER

First seen
2018-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Last IoC activity
2026-07-22 04:23:15
Profile updated
2026-07-07 11:49:20

Targeted industries: financial-services retail-and-hospitality

Context

NARWHAL SPIDER’s operation of Cutwail v2 was limited to country-specific spam campaigns, although late in 2019 there appeared to be an effort to expand by bringing in INDRIK SPIDER as a customer.

Reports & references

  • CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
  • secureworks.com — Gold Essex (report)
  • proofpoint.com — Brushaloader Still Sweeping Victims One Year Later (report)
  • proofpoint.com — Holiday Lull Not So Much (report)
  • proofpoint.com — Urlzone Top Malware Japan While Emotet And Line Phishing Round Out Landscape 0 (report)
  • proofpoint.com — Threat Actor Profile Ta544 Targets Geographies Italy Japan Range Malware (report)
  • proofpoint.com — Q4 2020 Threat Report Quarterly Analysis Cybersecurity Trends Tactics And Themes (report)
  • raw.githubusercontent.com — Microsoftmapping (report)

External references