TA2541

G1018

Threat group.View on attack.mitre.org

About this group

TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.

Techniques used28

Procedure examples28

TechniqueProcedure example
T1016.001
Internet Connection Discovery

TA2541 has run scripts to check internet connectivity from compromised hosts.

T1027.002
Software Packing

TA2541 has used a .NET packer to obfuscate malicious files.

T1027.013
Encrypted/Encoded File

TA2541 has used compressed and char-encoded scripts in operations.

T1027.015
Compression

TA2541 has used compressed and char-encoded scripts in operations.

T1036.005
Match Legitimate Resource Name or Location

TA2541 has used file names to mimic legitimate Windows files or system functionality.

T1047
Windows Management Instrumentation

TA2541 has used WMI to query targeted systems for security products.

T1053.005
Scheduled Task

TA2541 has used scheduled tasks to establish persistence for installed tools.

T1055
Process Injection

TA2541 has injected malicious code into legitimate .NET related processes including regsvcs.exe, msbuild.exe, and installutil.exe.

T1055.012
Process Hollowing

TA2541 has used process hollowing to execute CyberGate malware.

T1059.001
PowerShell

TA2541 has used PowerShell to download files and to inject into various Windows processes.

T1059.005
Visual Basic

TA2541 has used VBS files to execute or establish persistence for additional payloads, often using file names consistent with email themes or mimicking system functionality.

T1082
System Information Discovery

TA2541 has collected system information prior to downloading malware on the targeted host.

T1105
Ingress Tool Transfer

TA2541 has used malicious scripts and macros with the ability to download additional payloads.

T1204.001
Malicious Link

TA2541 has used malicious links to cloud and web services to gain execution on victim machines.

T1204.002
Malicious File

TA2541 has used macro-enabled MS Word documents to lure victims into executing malicious payloads.

View all 28 procedure examples

Software9

Campaigns0

None recorded.

References2

  1. Cisco Operation Layover September 2021 Open source
    Ventura, V. (2021, September 16). Operation Layover: How we tracked an attack on the aviation industry to five years of compromise. Retrieved September 15, 2023.
  2. Proofpoint TA2541 February 2022 Open source
    Larson, S. and Wise, J. (2022, February 15). Charting TA2541's Flight. Retrieved September 12, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.