NEW: Group Profiler — instant APT intel lookup. Try it →
Emblem illustrating the TA2541 threat group

TA2541

Overview

TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.

Naming & attribution

It uses 28 documented ATT&CK techniques — more than 62% of the 174 groups tracked here. Activity attributed since at least 2017.

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • APT-C-36 — 18 shared techniques (38% overlap)
  • LazyScripter — 13 shared techniques (37% overlap)
  • Confucius — 11 shared techniques (31% overlap)
  • Gamaredon Group Russia — 22 shared techniques (29% overlap)
  • TA505 — 14 shared techniques (29% overlap)
  • Sidewinder India — 13 shared techniques (29% overlap)

Malware families with tracked indicators

3 families attributed to TA2541, with 674 deduplicated indicators observed across abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL over the corpus's window (up to three years, as of 2026-09-26). MITRE documents what a group does; these are the indicators its malware families have surfaced in that window.

  • AgentTesla 662 indicators
  • RevengeRAT 6 indicators
  • NetWire 6 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Capabilities

  • Custom malware/implant development — ATT&CK: 7 attributed custom malware families

TTPs — 28 techniques across 8 tactics

Resource Development

Initial Access

Execution

Persistence

Defense Impairment

Command and Control

Tools & malware (9)

Snip3 · Revenge RAT · jRAT · WarzoneRAT · Imminent Monitor · AsyncRAT · NETWIRE · Agent Tesla · njRAT

Reporting (2)