TA2541 is a long-running cybercriminal threat actor active since at least 2017 and widely tracked for high-volume phishing campaigns that consistently target the aviation ecosystem and adjacent sectors. The actor is assessed to operate from Nigeria and has repeatedly targeted aviation, aerospace, transportation, manufacturing, and defense organizations, with recurring victim concentration across North America, Europe, and the Middle East. TA2541 is notable for persistence rather than sophistication: it relies on broad spray-and-pray email operations, transportation- and travel-themed social engineering, and commodity malware rather than bespoke tooling. TA2541 commonly uses malicious Microsoft Word documents, including macro-enabled attachments, to induce user execution, and later expanded to cloud-hosted delivery chains using links to hosted script payloads. The actor has staged malware on legitimate platforms and file-sharing services and has used obfuscated script-based downloaders that invoke PowerShell to retrieve additional payloads. Observed malware associated with TA2541 includes AsyncRAT, NetWire, WSH RAT, Parallax, AgentTesla, Imminent Monitor, STRRAT, Revenge RAT, VenomRAT, CyberGate, and vjw0rm. The group has also used malware strains acquired from criminal forums or open-source repositories, reinforcing its profile as a commodity-malware operator. Operationally, TA2541 has demonstrated repeated use of mshta for script execution, PowerShell-based execution chains, and process hollowing or related process injection techniques to run payloads within legitimate Windows processes. The actor performs host reconnaissance and security software discovery, including collection of system information and identification of antivirus, firewall, and other defensive products, and has attempted to disable built-in Windows protections before deploying remote access trojans. Persistence mechanisms observed in TA2541 intrusions include Startup-folder VBS files, Registry Run keys, and scheduled tasks. TA2541’s campaigns are characterized by large email volumes sent to many organizations rather than tightly tailored espionage tradecraft. Its malware set supports remote control, information gathering, and follow-on post-compromise activity. The actor’s sustained focus on aviation-related lures and organizations, combined with recurring use of commodity RATs and inexpensive infrastructure, makes it a persistent financially motivated cybercrime threat rather than a nation-state espionage actor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 malware families attributed to this actor across reporting.
10 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Listed as an associated threat actor in detection annotations for Ghostscript exploitation; no specific campaign activity is described in this reference.
Mentioned only as an annotated threat actor associated with the ATT&CK technique Process Injection (T1055) in a Splunk detection entry; no campaign or activity is described.
Mentioned only as an annotation/tag associated with the ATT&CK technique Process Injection (T1055); no campaign or activity by this group is described in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.