NARWHAL SPIDER
Aliases: GOLD ESSEX, TA544, Storm-0302, NARWHAL SPIDER
- First seen
- 2018-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Last IoC activity
- 2026-07-22 04:23:15
- Profile updated
- 2026-07-07 11:49:20
Targeted industries: financial-services retail-and-hospitality
Context
NARWHAL SPIDER’s operation of Cutwail v2 was limited to country-specific spam campaigns, although late in 2019 there appeared to be an effort to expand by bringing in INDRIK SPIDER as a customer.
Reports & references
- CrowdStrike — Report2020Crowdstrikeglobalthreatreport (report)
- secureworks.com — Gold Essex (report)
- proofpoint.com — Brushaloader Still Sweeping Victims One Year Later (report)
- proofpoint.com — Holiday Lull Not So Much (report)
- proofpoint.com — Urlzone Top Malware Japan While Emotet And Line Phishing Round Out Landscape 0 (report)
- proofpoint.com — Threat Actor Profile Ta544 Targets Geographies Italy Japan Range Malware (report)
- proofpoint.com — Q4 2020 Threat Report Quarterly Analysis Cybersecurity Trends Tactics And Themes (report)
- raw.githubusercontent.com — Microsoftmapping (report)