NARWHAL SPIDER

Also known as: GOLD ESSEX, TA544, Storm-0302, NARWHAL SPIDER, Narwhal Spider

NARWHAL SPIDER’s operation of Cutwail v2 was limited to country-specific spam campaigns, although late in 2019 there appeared to be an effort to expand by bringing in INDRIK SPIDER as a customer.

Introduction

NARWHAL SPIDER’s operation of Cutwail v2 was limited to country-specific spam campaigns, although late in 2019 there appeared to be an effort to expand by bringing in INDRIK SPIDER as a customer.

Activities and Tactics

Information pending cataloguing.

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

Information pending cataloguing.

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • URLZone:
  • Ursnif:
  • Panda Banker:
  • Nymaim:
  • Chthonic:
  • Smoke Loader:

Attribution and Evidence

Information pending cataloguing.

References

References pending cataloguing.