TA2541 is a persistent financially motivated cybercrime threat actor active since at least 2017. The actor is best known for large-scale email-based malware delivery campaigns that heavily impersonate aviation, aerospace, transportation, and travel-related entities, and it has also targeted defense and manufacturing organizations. Victim organizations have been observed globally, with recurring concentration in North America, Europe, and the Middle East. TA2541 is primarily associated with phishing operations that use aviation- and transportation-themed social engineering lures, typically in English, to induce user execution. Earlier campaigns commonly relied on macro-enabled Microsoft Word documents, while later activity shifted toward links to cloud-hosted payloads and script-based download chains. The actor has staged malware on legitimate services and public platforms, including cloud storage and code-sharing sites, to blend delivery into normal traffic patterns and reduce infrastructure costs. The group is notable for using a broad set of commodity remote access trojans rather than bespoke malware. Reported payloads associated with TA2541 include AsyncRAT, NetWire, WSH RAT, Parallax, Agent Tesla, Imminent Monitor, STRRAT, Revenge RAT, vjw0rm, and occasionally VenomRAT. This tooling diversity, combined with recurring lure themes and similar infection chains, is consistent with a cybercriminal operator that acquires malware from criminal forums or open-source repositories and swaps payload families over time while preserving delivery tradecraft. Observed execution chains frequently involve script-based staging, especially obfuscated Visual Basic Script and PowerShell. TA2541 has used PowerShell to download additional payloads and to inject code into Windows processes. The actor has also performed host reconnaissance before full payload deployment, including system information discovery and checks for installed security products such as antivirus and firewall software, sometimes via WMI. Defense evasion behavior has included attempts to weaken or disable built-in Windows security protections. For persistence, TA2541 has repeatedly used Windows autorun mechanisms, including Startup-folder VBS files and Registry Run keys, and has also used scheduled tasks. In campaigns involving AsyncRAT and other commodity RATs, persistence commonly ensured re-execution at logon and continued remote access after reboot. The actor has also used filenames intended to resemble legitimate Windows components or normal system functionality. TA2541 is widely assessed as a cybercriminal rather than a state-sponsored espionage actor. That assessment is supported by its use of commodity malware, broad and repeated sector targeting, high-volume phishing operations, and operational patterns centered on scalable malware distribution rather than stealthy long-term intelligence collection. No widely adopted alternate alias is more prominent than TA2541.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 malware families attributed to this actor across reporting.
9 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an annotated threat actor associated with the ATT&CK technique Process Injection (T1055) in a Splunk detection entry; no campaign or activity is described.
Mentioned only in an annotation/list associated with the detection content; no actor-specific activity is described in this reference.
Mentioned only in the detection annotation metadata; no campaign activity or actor-specific behavior is described in this content.
Listed in annotations alongside ATT&CK technique metadata for the detection; no campaign or activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.