This talk will cover two main topics: - An overview of a threat actor I have been tracking during my time working in PwC's Threat Intelligence team, known in the open source community as "Dark Caracal", and tracked by PwC as White Troll. - An look into some of the unique behaviours of White Troll, and how these can be used to track any newer activity.