Threat group.View on attack.mitre.org
TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.
| Technique | Procedure example |
|---|---|
| T1016.001 Internet Connection Discovery |
TA2541 has run scripts to check internet connectivity from compromised hosts. |
| T1027.002 Software Packing |
TA2541 has used a .NET packer to obfuscate malicious files. |
| T1027.013 Encrypted/Encoded File |
TA2541 has used compressed and char-encoded scripts in operations. |
| T1027.015 Compression |
TA2541 has used compressed and char-encoded scripts in operations. |
| T1036.005 Match Legitimate Resource Name or Location |
TA2541 has used file names to mimic legitimate Windows files or system functionality. |
| T1047 Windows Management Instrumentation |
TA2541 has used WMI to query targeted systems for security products. |
| T1053.005 Scheduled Task |
TA2541 has used scheduled tasks to establish persistence for installed tools. |
| T1055 Process Injection |
TA2541 has injected malicious code into legitimate .NET related processes including regsvcs.exe, msbuild.exe, and installutil.exe. |
| T1055.012 Process Hollowing |
TA2541 has used process hollowing to execute CyberGate malware. |
| T1059.001 PowerShell |
TA2541 has used PowerShell to download files and to inject into various Windows processes. |
| T1059.005 Visual Basic |
TA2541 has used VBS files to execute or establish persistence for additional payloads, often using file names consistent with email themes or mimicking system functionality. |
| T1082 System Information Discovery |
TA2541 has collected system information prior to downloading malware on the targeted host. |
| T1105 Ingress Tool Transfer |
TA2541 has used malicious scripts and macros with the ability to download additional payloads. |
| T1204.001 Malicious Link |
TA2541 has used malicious links to cloud and web services to gain execution on victim machines. |
| T1204.002 Malicious File |
TA2541 has used macro-enabled MS Word documents to lure victims into executing malicious payloads. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.