Uptime Hamster: 21d 18h 28mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza NARWHAL SPIDER

NARWHAL SPIDER

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Aliases: GOLD ESSEX, Storm-0302, TA544, Panda Banker, Narwhal Spider, URLZone, Ursnif, Nymaim, Chthonic, Smoke Loader, Online banking
Ver en IntelTracker → APTTrail →
NARWHAL SPIDER is a financially motivated criminal actor that emerged around 2007, primarily known for operating the Cutwail version 2 spam botnet. The group, often linked to Russia, provides spam services to other prolific cybercriminal entities, distributing various malware families. Over time, NARWHAL SPIDER has evolved to directly engage in ransomware deployment and complex phishing campaigns, demonstrating adaptability in its operational model. A distinguishing characteristic is its use of sophisticated evasion techniques, including steganography and the WikiLoader malware, to deliver payloads and avoid detection. This group operates under several aliases, including GOLD ESSEX, Storm-0302, and TA544.

Aliases del actor

GOLD ESSEXStorm-0302TA544Panda BankerNarwhal SpiderURLZoneUrsnifNymaimChthonicSmoke LoaderOnline banking

Actores similares

Scattered Spiderthreat-actor · 2doppel-spideractor · 1salty-spideractor · 1brain-spideractor · 1skeleton-spideractor · 1bamboo-spideractor · 1andromeda-spideractor · 1cobalt-spideractor · 1boson-spideractor · 1dextorous-spideractor · 1
Tecnicas MITRE
T1106, T1033, T1140, T1110, T1505, T1053
CVEs relacionadas
CVE-2024-2194, CVE-2023-6961, CVE-2023-40000
Tipo
apt
Pais origen
RU
Motivacion
-
Impacto
13
Actualizado
Wed, 01 Ju

Sectores objetivo (OSINT)

Professional&Technical ServicesOffices of Certified Public AccountantsOffices of Lawyers