TA2541
Description
(Proofpoint) TA2541 is a persistent cybercriminal actor that distributes various remote access trojans (RATs) targeting the aviation, aerospace, transportation, and defense industries, among others. Proofpoint has tracked this threat actor since 2017, and it has used consistent tactics, techniques, and procedures (TTPs) in that time. Entities in the targeted sectors should be aware of the actor’s TTPs and use the information provided for hunting and detection.
Names
Name | Name-Giver |
---|---|
TA2541 | Proofpoint |
Country
Motivation
- Information theft and espionage
First Seen
2017
Observed Sectors
Tools
- Agent Tesla
- AsyncRAT
- Ave Maria
- DarkRAT
- H-Worm
- Imminent Monitor RAT
- Luminosity RAT
- NetWire RC
- Parallax RAT
- RevengeRAT
Information
Other Information
Uuid
c830c769-f4d2-4c55-a77b-14632333e7d2
Last Card Change
2022-04-03