TA2541
MITRE ATT&CK: G1018 View on attack.mitre.org
Aliases: TA2541
- First seen
- 2017-01-01 00:00:00
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:00:56
Targeted industries: defense-and-aerospace transportation-and-logistics manufacturing
Context
TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.
Detection coverage
- 20 YARA rules
- 689 Sigma rules
Malware & tools used
- Upload Malware (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Asymmetric Cryptography (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Dynamic Resolution (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Security Software Discovery (attack-pattern)
- Scheduled Task (attack-pattern)
- Software Packing (attack-pattern)
- System Information Discovery (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Malware (attack-pattern)
- Mshta (attack-pattern)
- Tool (attack-pattern)
- Malicious Link (attack-pattern)
- Domains (attack-pattern)
- Process Injection (attack-pattern)
- PowerShell (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Internet Connection Discovery (attack-pattern)
- Process Hollowing (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Malicious File (attack-pattern)
- Visual Basic (attack-pattern)
- Spearphishing Link (attack-pattern)
Reports & references
- proofpoint.com — Charting Ta2541S Flight (report)
- MITRE ATT&CK — G1018 (report)
- Cisco Talos — Operation Layover How We Tracked Attack (report)