TA2541 is a Nigeria-linked cybercrime threat actor active since at least 2017. It conducts high-volume, opportunistic phishing campaigns, principally against aviation, aerospace, transportation, manufacturing, and defense organizations. Its campaigns have targeted organizations globally, with recurring activity affecting North America, Europe, and the Middle East. TA2541 commonly uses transportation-themed lures and malicious Microsoft Word documents, and later incorporated cloud-hosted payload links, to deliver commodity remote-access trojans including AsyncRAT, NetWire, WSH RAT, and Parallax. TA2541 relies primarily on publicly available or commercially obtainable malware rather than bespoke tooling. Its Windows attack chains have used Visual Basic Script, mshta, and PowerShell to retrieve and execute payloads. The actor performs system-information collection and security-software discovery, including WMI-based checks for antivirus and firewall products, and has attempted to impair built-in defenses. It has also used process hollowing to execute malware and established persistence through Startup-folder payloads and Registry Run keys. TA2541's operational objective is not conclusively established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 malware families attributed to this actor across reporting.
10 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TA2541 appears only in the detection's annotations list.
Listed as one of many threat actors associated with the detection's ATT&CK-style annotations for PowerShell and DNS TXT command-and-control behavior; no specific campaign or activity is described in this reference.
Listed as an associated threat actor in detection annotations for Ghostscript exploitation; no specific campaign activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.