top of page
Mitre
Alias
Ta2541
Country
[unknown]
Sponsor
Nil
Motivation
Information Theft And Espionage
First Seen
2017
Description
(Proofpoint) TA2541 is a persistent cybercriminal actor that distributes various remote access trojans (RATs) targeting the aviation, aerospace, transportation, and defense industries, among others. Proofpoint has tracked this threat actor since 2017, and it has used consistent tactics, techniques, and procedures (TTPs) in that time. Entities in the targeted sectors should be aware of the actor's TTPs and use the information provided for hunting and detection.
Targeted
Industries
Aviation, Aerospace, Defense, Transportation
Targeted
Countries
Nil
Tools
Agent Tesla
Asyncrat
Ave Maria
Darkrat
H-worm
Imminent Monitor Rat
Luminosity Rat
Netwire Rc
Parallax Rat
Revengerat
TTP
Nil
Operations
Performed
Nil
Counter
Operations
Nil
Information
bottom of page