TA2541 is a financially motivated cybercrime group targeting aviation sectors since 2017.
Analyst brief
TA2541 is a persistent, financially motivated cybercrime group active since at least 2017. This actor primarily targets aviation, aerospace, transportation, manufacturing, and defense industries. TA2541 relies on spearphishing campaigns themed around aviation and travel for initial access, followed by TTPs like persistence establishment to deploy an array of RATs including Revenge RAT, AsyncRAT, Agent Tesla, and njRAT. Defenders should monitor for persistence mechanisms (e.g., Scheduled Tasks, Registry Run Keys), block suspicious spearphishing attempts, and track C2 traffic using Asymmetric Cryptography associated with these RATs.
TA2541
unknown
Persistent cybercrime threat actor targeting aviation, aerospace, transportation, manufacturing, and defense industries for years. This threat actor consistently uses remote access trojans (RATs) that can be used to remotely control compromised machines. This threat actor uses consistent themes related to aviation, transportation, and travel. The threat actor has used similar themes and targeting since 2017.