TA2541
Overview
TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.
Naming & attribution
TA2541 is tracked under 1 names across the industry. It uses 28 documented ATT&CK techniques — more than 62% of the 174 groups tracked here. Activity attributed since at least 2017.
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- APT-C-36 — 18 shared techniques (38% overlap)
- LazyScripter — 13 shared techniques (37% overlap)
- Confucius — 11 shared techniques (31% overlap)
- Gamaredon Group Russia — 22 shared techniques (29% overlap)
- TA505 — 14 shared techniques (29% overlap)
- Sidewinder India — 13 shared techniques (29% overlap)
Malware families with current indicators
5 families attributed to TA2541, carrying 788 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.
- AgentTesla 254 indicators
- RevengeRAT 251 indicators
- NetWire 251 indicators
- jRAT 30 indicators
- AsyncRat 2 indicators
Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.
Capabilities
- Custom malware/implant development — ATT&CK: 7 attributed custom malware families
TTPs — 28 techniques across 8 tactics
Resource Development
-
T1583.001Domains -
T1583.006Web Services -
T1588.001Malware -
T1588.002Tool -
T1608.001Upload Malware
Initial Access
-
T1566.001Spearphishing Attachment -
T1566.002Spearphishing Link
Execution
-
T1047Windows Management Instrumentation -
T1053.005Scheduled Task -
T1059.001PowerShell -
T1059.005Visual Basic -
T1204.001Malicious Link -
T1204.002Malicious File
Persistence
-
T1547.001Registry Run Keys / Startup Folder
Stealth
-
T1027.002Software Packing -
T1027.013Encrypted/Encoded File -
T1027.015Compression -
T1036.005Match Legitimate Resource Name or Location -
T1055Process Injection -
T1055.012Process Hollowing -
T1218.005Mshta
Defense Impairment
-
T1685Disable or Modify Tools
Discovery
-
T1016.001Internet Connection Discovery -
T1082System Information Discovery -
T1518.001Security Software Discovery
Command and Control
-
T1105Ingress Tool Transfer -
T1568Dynamic Resolution -
T1573.002Asymmetric Cryptography
Tools & malware (9)
Snip3 · Revenge RAT · jRAT · WarzoneRAT · Imminent Monitor · AsyncRAT · NETWIRE · Agent Tesla · njRAT
Reporting (2)
- Charting TA2541's Flight — Larson, S. and Wise, J
- Operation Layover: How we tracked an attack on the aviation industry to five years of compromise — Ventura, V