GOLD ESSEX is a cybercriminal threat actor associated with the Cutwail botnet and tracked as TA544 and Narwhal Spider. It is known for operating large-scale spam distribution infrastructure used to deliver malware for financially motivated campaigns. High-confidence reporting links GOLD ESSEX’s Cutwail botnet to malware delivery operations involving Dridex distribution in 2020. The actor’s core role is initial access through spam-based malware delivery. Its activity is characterized by mass email distribution and botnet-enabled payload dissemination on behalf of broader criminal operations. The available evidence directly supports GOLD ESSEX’s use of spam campaigns as a delivery mechanism, but does not provide sufficient high-confidence detail here on its full victimology, geographic focus, or broader post-compromise tradecraft. Known aliases include TA544 and Narwhal Spider.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the operator of the Cutwail botnet used to distribute spam leading to Dridex campaigns.
Referenced as the operator of the Cutwail botnet used to distribute spam leading to Dridex campaigns.
Named as a criminal group observed using the Pony/Fareit malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.