TA544, also known as Narwhal Spider and Storm-0302, is a financially motivated cybercrime threat actor best known for high-volume malicious email campaigns delivering banking malware and other first-stage payloads. The actor has been tracked since 2017 and is notable for geographically focused operations, especially against targets in Italy and Japan, with earlier or more limited activity also observed against Germany, Poland, and Spain. TA544 is widely assessed as an affiliate-style malware distributor or initial access facilitator that has worked with multiple malware ecosystems rather than a single exclusive payload set. TA544 initially appeared in campaigns targeting Italian users with Panda Banker and later expanded to distribute Chthonic, Smoke Loader, Nymaim, ZLoader, URLZone, Dridex, IcedID, DanaBot, and multiple Ursnif variants. By 2019, Ursnif and URLZone had become especially associated with the actor. In Japan, TA544 commonly used malicious Excel documents with macros to install URLZone, which then deployed Ursnif configured for Japanese banking targets. In Italy, the actor distributed several Ursnif affiliate variants in localized campaigns. TA544 has also been observed using BrushaLoader and, in limited campaigns during 2022, IcedID; in February 2024 it was observed delivering DanaBot. The actor relies primarily on email-based initial access using localized social-engineering lures such as invoice, payment, billing, and brand-themed messages. Delivery mechanisms have included malicious Microsoft Office documents with macros, password-protected archives, compressed script attachments, and links leading to staged malware delivery. TA544 is particularly associated with heavy obfuscation, geofencing, and steganography. Campaigns have used locale and language checks to verify victims are in the intended geography, especially Japan, and have embedded concealed code in benign-looking images to evade detection. The actor’s campaigns are often tailored by language, branding, and theme to the target region. TA544 has sent very large volumes of malicious email and has been described as one of the more prolific geographically focused eCrime actors. Its activity has also been linked to malware delivery chains that can enable later-stage ransomware intrusions, consistent with the broader role of banking trojan and loader operators as access providers within the cybercrime ecosystem. Reported email activity declined significantly from mid-2024, in line with a broader reduction in prominent initial access broker and loader-driven malspam operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named threat actor referenced in global threat reporting.
Ecrime actor observed delivering DanaBot in a 2024 campaign; its initial access activity has previously been associated with ransomware infections.
Tracked initial access broker whose email campaign activity decreased or disappeared since mid-2024.
Referenced as an IcedID-affiliated activity cluster distinguished by themed IcedID bot campaign IDs (Italian references). No additional operational details provided in this content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.