Researchers linked a long-running cybercrime actor tracked as TA2541 to years of phishing campaigns against aviation, aerospace, transportation, manufacturing, and defense organizations. Cisco Talos and Proofpoint assessed the actor as likely operating from Nigeria, using aviation- and travel-themed lures such as fake itineraries, charter details, and regulator impersonation to trick targets into opening malicious documents or cloud-hosted payload links. The campaigns have delivered commodity remote access trojans including AsyncRAT, njRAT, NetWire, WSH RAT, Parallax, AgentTesla, STRRAT, Imminent Monitor, and vjw0rm, with recurring infrastructure and identifiers such as dynamic DNS domains and keywords including "kimjoy," "h0pe," and "grace."
The intrusion chains evolved over time but remained operationally consistent: earlier waves used macro-enabled Word files, while later activity shifted to Google Drive, OneDrive, and Discord links hosting VBS payloads. Talos documented more complex stages involving malicious Publisher macros, mshta, PowerShell, AMSI bypass code, and GitHub-hosted payloads, while Fortinet described a campaign in which a Google Drive-delivered VBS script dropped XML with inline C# code, used MSBuild.exe for execution, and hollowed RegSvcs.exe to inject AsyncRAT, likely with ties to Snip3 Crypter infrastructure. Despite limited technical sophistication, the actor has maintained multi-year access operations that enable credential theft, fraud, and potential access brokerage across aviation-related targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
Proofpoint observed TA2541 using Imminent Monitor with scheduled-task and registry-based persistence in November 2021. The activity showed the actor continuing to vary payloads while maintaining similar infection-chain behavior.
Talos identified eight additional domains linked to the campaign, most of which were first seen in May or June 2021. This expanded the infrastructure cluster associated with the aviation-targeting actor.
Fortinet said the sender IP 192.145.239.18 used in a later aviation phishing campaign had also been associated with an aviation-themed Snip3 Crypter campaign observed in April and May 2021. The overlap in sender IP, C2 IP, and payload supported a likely link to Snip3 Crypter-as-a-service.
Proofpoint observed TA2541 using DiscordApp URLs in late 2021 to deliver compressed files that installed AgentTesla or Imminent Monitor. This reflected an evolution in delivery methods beyond macro-enabled documents and cloud-hosted VBS links.
Proofpoint observed TA2541 using COVID-19-themed phishing lures in spring 2020, including cargo shipments of PPE and COVID-19 testing kits. This represented a temporary thematic shift within the actor's broader transportation-focused social engineering.
Fortinet reported that IP address 79.134.225.18, later used by the aviation campaign's franco.ddns.net C2, had been linked since 2019 to AsyncRAT/RevengeRAT, NanoCore, and botnet attacks. This provided historical context for the infrastructure used in the campaign.
Talos found evidence that a user named Nassief had purchased the Aspire crypter by December 2018. This crypter was later linked to infrastructure and samples associated with the aviation campaign.
Talos found samples communicating with akconsult.linkpc.net that showed aviation-related targeting beginning in August 2018. This marked the start of the actor's documented aviation-focused activity in Talos' dataset.
Proofpoint reported that the threat actor it tracks as TA2541 had been conducting persistent malware campaigns since January 2017. The actor targeted aviation, aerospace, transportation, manufacturing, and defense organizations with phishing-delivered commodity RATs.
A sample associated with groups.us.to was first seen using a batch file in a multi-stage malware chain. Talos treated this infrastructure as a lower-confidence but potentially related link to the same actor.
The domain akconsult.linkpc.net, later tied to aviation-themed malware campaigns, was first observed. Talos later linked it to recent AsyncRAT activity and broader actor infrastructure.
Talos identified four additional samples using the same malware family and different identifiers, expanding the historical footprint of the actor's activity. These samples were seen between September 2012 and May 2014.
A malware sample using CyberGate RAT and the identifier "Akconsult" was first seen, providing one of the earliest artifacts later linked to the TA2541/Operation Layover activity cluster. The sample communicated with the C2 domain opybiddo.zapto.org.
BleepingComputer summarized Proofpoint's findings that TA2541 had targeted aviation and related sectors for years using large-scale phishing and commodity RATs. The report also highlighted overlap with Cisco Talos' earlier attribution of similar activity to a Nigeria-based actor.
Proofpoint published a report charting TA2541's long-running campaigns since 2017, its sector targeting, and its shift from macro-enabled Word documents to cloud-hosted payload links. The company assessed the actor as a financially motivated cybercriminal using commodity malware and recurring infrastructure patterns.
Cisco Talos published research linking aviation-themed malware campaigns to a single Nigeria-based threat actor active for roughly five to six years. Talos connected domains, handles, and malware samples showing long-running use of commodity RATs and crypters against aviation targets.
FortiGuard Labs described a spear-phishing campaign targeting aviation companies with fake federal aviation authority emails and Google Drive links disguised as PDFs. The infection chain used a VBS script, an XML payload compiled by MSBuild.exe, and a RunPE-style loader to inject AsyncRAT into RegSvcs.exe.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
blog.morphisec.com
Open sourcebleepingcomputer.com
Open sourceproofpoint.com
Open sourceblog.talosintelligence.com
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.