TA2541
TA2541 is a persistent cybercriminal threat actor tracked by Proofpoint that has conducted malware campaigns since at least January 2017. It targets organizations in the aviation, aerospace, transportation, manufacturing, and defense sectors, using aviation-, transportation-, and travel-themed social engineering lures and often impersonating aviation firms. Campaigns have affected hundreds of organizations globally, with recurring targets in North America, Europe, and the Middle East. Proofpoint assesses TA2541 as financially motivated rather than espionage-focused, based on its use of commodity malware, broad targeting, high-volume phishing, and recurring infrastructure patterns. TA2541 primarily gains initial access through phishing emails, usually in English, with malicious attachments or links. It historically used macro-enabled Microsoft Word documents and has also used RAR archives containing executables. Later campaigns shifted toward links to cloud-hosted payloads on services such as Google Drive, and in some cases DiscordApp URLs. TA2541 has uploaded or staged malware on Google Drive, Pastetext, Sharetext, GitHub, and paste.ee. The actor distributes commodity remote access trojans and has used more than a dozen malware payloads since 2017. AsyncRAT is identified as its current preferred payload. Other malware associated with TA2541 includes NetWire, WSH RAT, Parallax, AgentTesla, Imminent Monitor, STRRAT, Revenge RAT, vjw0rm, and occasionally VenomRAT. TA2541 has also used multiple malware strains available for purchase on criminal forums or in open-source repositories. Observed tradecraft includes obfuscated VBS files that launch PowerShell to retrieve malware, PowerShell-based downloading and injection into Windows processes, WMI queries to identify security products, collection of system information before downloading RAT payloads, attempts to disable built-in Windows security protections including AMSI, use of TLS-encrypted C2 communications including with AsyncRAT, compressed and char-encoded scripts, and masquerading via filenames that mimic legitimate Windows files or system functionality. TA2541 has established persistence through VBS files in the Startup folder, scheduled tasks, and Windows Registry Run keys. Proofpoint also noted recurring infrastructure characteristics including use of VPS-based email infrastructure, Dynamic DNS for C2, and repeated keywords such as "kimjoy," "h0pe," and "grace."
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
14 malware families attributed to this actor across reporting.
9 additional families tracked in Mallory.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Listed as a threat actor associated with PowerShell execution behavior relevant to this detection analytic.
Listed as a threat actor associated with the malicious file execution technique detected by this analytic.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.