Narwhal Spider

Description

(CrowdStrike) CrowdStrike Falcon Intelligence has observed a new Cutwail spam campaign from NARWHAL SPIDER on 24 October 2018. NARWHAL SPIDER is the adversary name designated by Falcon Intelligence for the criminal operator of Cutwail version 2. NARWHAL SPIDER primarily provides spam services with a large customer base that has included malware operators such as Wizard Spider, Gold Blackburn (developer of TrickBot), affiliates of BAMBOO SPIDER (developer of Panda Zeus), and many others including URLZone, Nymaim and Gozi ISFB. The targets and payloads delivered through Cutwail spam campaigns are determined by the customers of NARWHAL SPIDER.

Cutwail has been observed to distribute Dyre (Wizard Spider, Gold Blackburn), Zeus Panda (Bamboo Spider, TA544) and much of the malware from TA505, Graceful Spider, Gold Evergreen.

Names

NameName-Giver
Narwhal SpiderCrowdStrike
Gold EssexSecureWorks
Storm-0302Microsoft

Country

Motivation

  • Financial gain

First Seen

2007

Observed Countries

Tools

Operations

Counter Operations

Information

Other Information

Uuid

2b42c978-bc85-4aff-910d-b72e077b330f

Last Card Change

2025-06-28