TA2541

MITRE ATT&CK: G1018 View on attack.mitre.org

Aliases: TA2541

First seen
2017-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:00:56

Targeted industries: defense-and-aerospace transportation-and-logistics manufacturing

Context

TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.

Detection coverage

  • 20 YARA rules
  • 689 Sigma rules

Malware & tools used

  • Upload Malware (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Asymmetric Cryptography (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Dynamic Resolution (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Software Packing (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Malware (attack-pattern)
  • Mshta (attack-pattern)
  • Tool (attack-pattern)
  • Malicious Link (attack-pattern)
  • Domains (attack-pattern)
  • Process Injection (attack-pattern)
  • PowerShell (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Internet Connection Discovery (attack-pattern)
  • Process Hollowing (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Malicious File (attack-pattern)
  • Visual Basic (attack-pattern)
  • Spearphishing Link (attack-pattern)

Reports & references

  • proofpoint.com — Charting Ta2541S Flight (report)
  • MITRE ATT&CK — G1018 (report)
  • Cisco Talos — Operation Layover How We Tracked Attack (report)

External references