Uptime Hamster: 10d 8h 7mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza NARWHAL SPIDER

NARWHAL SPIDER

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Aliases: GOLD ESSEX, Storm-0302, TA544, Narwhal Spider, URLZone, Ursnif, Panda Banker, Nymaim, Chthonic, Smoke Loader, Online banking
Ver en IntelTracker → APTTrail →
NARWHAL SPIDER is a financially motivated criminal actor that emerged around 2007, primarily known for operating the Cutwail version 2 spam botnet. The group, often linked to Russia, provides spam services to other prolific cybercriminal entities, distributing various malware families. Over time, NARWHAL SPIDER has evolved to directly engage in ransomware deployment and complex phishing campaigns, demonstrating adaptability in its operational model. A distinguishing characteristic is its use of sophisticated evasion techniques, including steganography and the WikiLoader malware, to deliver payloads and avoid detection. This group operates under several aliases, including GOLD ESSEX, Storm-0302, and TA544.

Aliases del actor

GOLD ESSEXStorm-0302TA544Narwhal SpiderURLZoneUrsnifPanda BankerNymaimChthonicSmoke LoaderOnline banking

Actores similares

Scattered Spideractor · 2Indrik Spideractor · 1doppel-spideractor · 1salty-spideractor · 1brain-spideractor · 1skeleton-spideractor · 1bamboo-spideractor · 1andromeda-spideractor · 1cobalt-spideractor · 1boson-spideractor · 1
Tecnicas MITRE
T1106, T1033, T1140, T1110, T1505, T1053
CVEs relacionadas
CVE-2024-2194, CVE-2023-6961, CVE-2023-40000
Tipo
apt
Pais origen
RU
Motivacion
-
Impacto
13
Actualizado
Wed, 01 Ju

Sectores objetivo (SOCRadar)

Professional&Technical ServicesOffices of Certified Public AccountantsOffices of Lawyers