THREAT_ACTOR · G1018
TA2541
Also known as: TA2541
Profile
TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.
MITRE ATT&CK ↗Techniques
28 ATT&CK techniques attributed to this actor.
T1016.001 Internet Connection DiscoveryT1027.002 Software PackingT1027.013 Encrypted/Encoded FileT1027.015 CompressionT1036.005 Match Legitimate Resource Name or LocationT1047 Windows Management InstrumentationT1053.005 Scheduled TaskT1055 Process InjectionT1055.012 Process HollowingT1059.001 PowerShellT1059.005 Visual BasicT1082 System Information DiscoveryT1105 Ingress Tool TransferT1204.001 Malicious LinkT1204.002 Malicious FileT1218.005 MshtaT1518.001 Security Software DiscoveryT1547.001 Registry Run Keys / Startup FolderT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1568 Dynamic ResolutionT1573.002 Asymmetric CryptographyT1583.001 DomainsT1583.006 Web ServicesT1588.001 MalwareT1588.002 ToolT1608.001 Upload MalwareT1685 Disable or Modify Tools
Software
9 malware/tools attributed to this actor.
NETWIREjRATAgent TeslaRevenge RATnjRATImminent MonitorWarzoneRATSnip3AsyncRAT
Related corpus activity
9,928 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to TA2541.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 9,928.