NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / TA2541

TA2541

Overview

TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.

Capabilities

  • Custom malware/implant development — ATT&CK: 7 attributed custom malware families

TTPs — 28 techniques across 8 tactics

Resource Development

Initial Access

Execution

Persistence

Defense Impairment

Command and Control

Tools & malware (9)

Snip3 · Revenge RAT · jRAT · WarzoneRAT · Imminent Monitor · AsyncRAT · NETWIRE · Agent Tesla · njRAT

Reporting (2)