TA2541

APT / StateG1018 ↗
Techniques (MITRE ATT&CK)28
SourceMITRE ATT&CK
0

About the group

TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity35
Impact: High
T1566.001T1047T1547.001ENTRYInitial accessSpearphishingAttachmentEXECExecutionWindows ManagementInstrumentationPERSPersistenceRegistry Run Keys/ Startup FolderDISCDiscoveryInternetConnection Discov…

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 15522

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

domainmatefalls.pages.devjRATthreatfox
domainmatefallsbeta.pages.devjRATthreatfox
ip:port196.77.102.208:8808AsyncRATthreatfox
ip:port64.89.160.127:2021AsyncRATthreatfox
ip:port46.246.84.5:2703AsyncRATthreatfox
ip:port186.169.33.116:9140AsyncRATthreatfox
ip:port157.20.182.14:9992AsyncRATthreatfox
ip:port128.90.105.180:8081AsyncRATthreatfox
urlhttp://wp.fujeigroup.com:8888/file/img_154255.pngAsyncRATurlhaus
sha256_hash7c66d0c75e6bb948f52ca677c5d34b372d974f8b06aecffba092881cfb763081AsyncRATmalwarebazaar
md5_hash22f8ba22b4c9d92415c0f1098c3f90f1AsyncRATthreatfox
sha1_hash5db5024f0f0ee36682ddf4aa069f70a848475638AsyncRATthreatfox
sha256_hash1581428fe60e65944ab96f61965c9317552ab64292858d3a64f885226b88528fAsyncRATthreatfox
ip:port46.246.12.6:7049AsyncRATthreatfox
ip:port192.162.199.186:8808AsyncRATthreatfox
ip:port172.94.46.114:3030AsyncRATthreatfox
ip:port144.79.249.51:4444AsyncRATthreatfox
ip:port217.60.103.15:8808AsyncRATthreatfox
ip:port217.165.57.21:7707AsyncRATthreatfox
ip:port192.162.199.186:6606AsyncRATthreatfox
ip:port104.243.248.63:411AsyncRATthreatfox
sha256_hash791c80619bb5c1dcd0a560c419b8e32885d074c82f626a1f35d4f477a45eb344AsyncRATthreatfox
sha1_hash36bebfe8d53c60e5b97c084bf6e0b4bb94e457fdAsyncRATthreatfox
md5_hash61480a155193ab1d60ede49b5fe13556AsyncRATthreatfox
sha256_hash0fecb72b1e5b1fc4f5a00fec90beb85b22b6ec9be8139dd4cdf448087decefd5AsyncRATthreatfox
sha1_hashc51dca474e7874c4b1056499e4df10dfec3d5afeAsyncRATthreatfox
md5_hashd9e3aad9d528c2cbcf57362306e6b5dfAsyncRATthreatfox
ip:port46.246.14.5:5064AsyncRATthreatfox
ip:port192.162.199.186:7707AsyncRATthreatfox
ip:port128.90.112.16:8081AsyncRATthreatfox

+15522 indicators in total. See them all on the IOCs page.

TA2541 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →