TA2541 is a persistent financially motivated cybercriminal threat actor active since at least 2017 and best known for phishing-led malware delivery against aviation-related targets. The actor has repeatedly targeted organizations in the aviation, aerospace, transportation, manufacturing, and defense sectors, while also affecting a broader set of organizations globally, with recurring activity concentrated in North America, Europe, and the Middle East. TA2541 commonly uses aviation-, transportation-, and travel-themed social engineering, often impersonating aviation firms and sending high-volume English-language phishing campaigns. TA2541 primarily distributes commodity remote access trojans and related malware, including AsyncRAT, NetWire, WSH RAT, Parallax, AgentTesla, Imminent Monitor, STRRAT, Revenge RAT, vjw0rm, and at times VenomRAT. The actor has also used multiple malware strains obtainable through criminal forums or open-source repositories, reinforcing its characterization as a cybercrime operator rather than a state-sponsored espionage group. Its delivery chains have evolved over time. Earlier campaigns relied heavily on macro-enabled Microsoft Word attachments, while later activity shifted toward links to cloud-hosted payloads and scripts on legitimate platforms. TA2541 has staged malware on services such as Google Drive, GitHub, and text-sharing platforms, and has also used archive attachments and cloud-hosted intermediary files. A common execution pattern involves obfuscated script-based downloaders that launch PowerShell to retrieve and run follow-on payloads. Post-compromise, TA2541 has demonstrated system information discovery, security software discovery, and defense evasion. The actor has collected host information before downloading final payloads, queried Windows Management Instrumentation and other mechanisms to identify antivirus and firewall products, and attempted to weaken built-in Windows security protections. TA2541 has also used file naming intended to mimic legitimate Windows files or normal system functionality. For persistence, TA2541 has used Startup-folder VBS files, Registry Run keys, and scheduled tasks. In multiple campaigns, VBS launchers in startup locations invoked PowerShell to maintain access and reload malware such as AsyncRAT. Execution tradecraft includes PowerShell-based downloading and process injection into Windows processes. TA2541 also uses TLS-encrypted command-and-control communications in some campaigns. Overall, TA2541 is a long-running malware distribution actor focused on scalable phishing operations, commodity RAT deployment, and repeatable infection chains tailored especially to aviation-adjacent organizations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
14 malware families attributed to this actor across reporting.
9 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
18 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an annotated threat actor associated with the ATT&CK technique Process Injection (T1055) in a Splunk detection entry; no campaign or activity is described.
Mentioned only in an annotation/list associated with the detection content; no actor-specific activity is described in this reference.
Mentioned only in the detection annotation metadata; no campaign activity or actor-specific behavior is described in this content.
Listed in annotations alongside ATT&CK technique metadata for the detection; no campaign or activity is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.