logo

TA2541__2022__Proofpoint_Charting-TA2541s-Flight_02-15-2022.pdf

ID: 6eb2f473-0e66-411c-8553-9066b92cf31b

STIX ID: report--6eb2f473-0e66-411c-8553-9066b92cf31b

Threat Score

78/100

Uploaded: 2026-08-20

Published Date: 2022-02-21

Last Modified Date: 2022-02-21

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Proofpoint's Threat Insight analyzes TA2541, a persistent cybercrime threat actor active since 2017 that targets aviation, aerospace, transportation, manufacturing, and defense sectors with a mix of remote access trojans (RATs) and commodity malware. The report details phishing-like lures featuring transportation themes, use of Google Drive/Discord CDN hosting for payloads, PowerShell-based download chains, and persistence techniques (startup scripts, scheduled tasks, registry Run keys), plus a broad set of IOCs and infrastructure patterns to aid hunting and detection.