top of page

TA2541

Mitre

Alias

Ta2541

Country

[unknown]

Sponsor

Nil

Motivation

Information Theft And Espionage

First Seen

2017

Description

(Proofpoint) TA2541 is a persistent cybercriminal actor that distributes various remote access trojans (RATs) targeting the aviation, aerospace, transportation, and defense industries, among others. Proofpoint has tracked this threat actor since 2017, and it has used consistent tactics, techniques, and procedures (TTPs) in that time. Entities in the targeted sectors should be aware of the actor's TTPs and use the information provided for hunting and detection.

Targeted
Industries

Aviation, Aerospace, Defense, Transportation

Targeted
Countries

Nil

Tools

Agent Tesla
Asyncrat
Ave Maria
Darkrat
H-worm
Imminent Monitor Rat
Luminosity Rat
Netwire Rc
Parallax Rat
Revengerat

TTP

Nil

Operations
Performed

Nil

Counter
Operations

Nil

Information

bottom of page