NARWHAL SPIDER
Also reported as Storm-0302, TA544, BAMBOO SPIDER, GOLD ESSEX, Narwhal Spider and 2 other names.
Reports per quarter
CVEs named in reports
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0262 KEV
- CVE-2017-11292 KEV
- CVE-2017-11882 KEV ransomware
- CVE-2017-8759 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2020-0688 KEV ransomware
- CVE-2020-10189 KEV
Show all 14 CVEs Show fewer
- CVE-2020-1472 KEV ransomware
- CVE-2020-2021 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Mummy Spider, TA542 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Mummy Spider, TA542 - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ISFB (Malware Family)
-
Smoky Spider - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Smoky Spider - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor FlawedAmmyy (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Dridex (Malware Family)
-
Wizard Spider, Gold Blackburn - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Wizard Spider, Gold Blackburn - Threat Group Cards: A Threat Actor Encyclopedia
-
Bamboo Spider, TA544 - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Bamboo Spider, TA544 - Threat Group Cards: A Threat Actor Encyclopedia
-
TA505, Graceful Spider, Gold Evergreen
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor TA505, Graceful Spider, Gold Evergreen
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ryuk (Malware Family)
Show all 35 reports Show fewer
-
Innovation in Cyber Intrusions: The Evolution of TA544 - Yoroi
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Innovation in Cyber Intrusions: The Evolution of TA544 - Yoroi
-
WailingCrab malware misuses MQTT messaging protocol
The original link failed its last check. Original publisher Detailsfor WailingCrab malware misuses MQTT messaging protocol
-
Fork in the Ice- The New Era of IcedID
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Fork in the Ice- The New Era of IcedID
-
TA544 Targets Italian Organizations with Ursnif Malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA544 Targets Italian Organizations with Ursnif Malware
-
The First Step- Initial Access Leads to Ransomware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The First Step- Initial Access Leads to Ransomware
-
Q4 2020 Threat Report- A Quarterly Analysis of Cybersecurity Trends, Tactics and Themes
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Q4 2020 Threat Report- A Quarterly Analysis of Cybersecurity Trends, Tactics and Themes
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor CERTFR-2020-CTI-008
-
BrushaLoader still sweeping up victims one year later
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BrushaLoader still sweeping up victims one year later
-
Threat Actor Profile- TA544 targets geographies from Italy to Japan with a range of malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Actor Profile- TA544 targets geographies from Italy to Japan with a range of malware
-
Cutwail Spam Campaign Uses Steganography to Distribute URLZone
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cutwail Spam Campaign Uses Steganography to Distribute URLZone
Newest first. Details opens the report in Explore.