TA2541

APT / EstatalG1018 ↗
Técnicas (MITRE ATT&CK)28
FuenteMITRE ATT&CK
0

Sobre el grupo

TA2541 is a cybercriminal group that has been targeting the aviation, aerospace, transportation, manufacturing, and defense industries since at least 2017. TA2541 campaigns are typically high volume and involve the use of commodity remote access tools obfuscated by crypters and themes related to aviation, transportation, and travel.

Cadena de ataque

Escenario plausible montado a partir de las técnicas reales del grupo, ordenadas por las fases de un ataque. Cada etapa muestra cómo suele actuar el grupo.

Severidad del arsenal35
Impacto: Alto
T1566.001T1047T1547.001ENTRYAcceso inicialSpearphishingAttachmentEXECEjecuciónWindows ManagementInstrumentationPERSPersistenciaRegistry Run Keys/ Startup FolderDISCDescubrimientoInternetConnection Discov…

Cadena ilustrativa derivada de las técnicas documentadas en MITRE ATT&CK — no representa un ataque específico ya ocurrido. La severidad resume el arsenal conocido (cobertura de la cadena, CVEs en explotación activa, técnicas).

Vulnerabilidades explotadas

Ninguna CVE atribuida a este grupo en las fuentes públicas (MITRE ATT&CK). La ausencia de atribución no significa ausencia de actividad.

Infraestructura conocida 15522

Indicadores reales (C2, dominios, URLs y hashes) asociados al malware que usa este grupo. Fuente: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

domainmatefalls.pages.devjRATthreatfox
domainmatefallsbeta.pages.devjRATthreatfox
ip:port196.77.102.208:8808AsyncRATthreatfox
ip:port64.89.160.127:2021AsyncRATthreatfox
ip:port46.246.84.5:2703AsyncRATthreatfox
ip:port186.169.33.116:9140AsyncRATthreatfox
ip:port157.20.182.14:9992AsyncRATthreatfox
ip:port128.90.105.180:8081AsyncRATthreatfox
urlhttp://wp.fujeigroup.com:8888/file/img_154255.pngAsyncRATurlhaus
sha256_hash7c66d0c75e6bb948f52ca677c5d34b372d974f8b06aecffba092881cfb763081AsyncRATmalwarebazaar
md5_hash22f8ba22b4c9d92415c0f1098c3f90f1AsyncRATthreatfox
sha1_hash5db5024f0f0ee36682ddf4aa069f70a848475638AsyncRATthreatfox
sha256_hash1581428fe60e65944ab96f61965c9317552ab64292858d3a64f885226b88528fAsyncRATthreatfox
ip:port46.246.12.6:7049AsyncRATthreatfox
ip:port192.162.199.186:8808AsyncRATthreatfox
ip:port172.94.46.114:3030AsyncRATthreatfox
ip:port144.79.249.51:4444AsyncRATthreatfox
ip:port217.60.103.15:8808AsyncRATthreatfox
ip:port217.165.57.21:7707AsyncRATthreatfox
ip:port192.162.199.186:6606AsyncRATthreatfox
ip:port104.243.248.63:411AsyncRATthreatfox
sha256_hash791c80619bb5c1dcd0a560c419b8e32885d074c82f626a1f35d4f477a45eb344AsyncRATthreatfox
sha1_hash36bebfe8d53c60e5b97c084bf6e0b4bb94e457fdAsyncRATthreatfox
md5_hash61480a155193ab1d60ede49b5fe13556AsyncRATthreatfox
sha256_hash0fecb72b1e5b1fc4f5a00fec90beb85b22b6ec9be8139dd4cdf448087decefd5AsyncRATthreatfox
sha1_hashc51dca474e7874c4b1056499e4df10dfec3d5afeAsyncRATthreatfox
md5_hashd9e3aad9d528c2cbcf57362306e6b5dfAsyncRATthreatfox
ip:port46.246.14.5:5064AsyncRATthreatfox
ip:port192.162.199.186:7707AsyncRATthreatfox
ip:port128.90.112.16:8081AsyncRATthreatfox

+15522 indicadores en total. Míralos todos en la página de IOCs.

El grupo TA2541 usa técnicas y explota fallas reales. El Pentest Autónomo con IA de TrueHacking simula esos ataques en tu infraestructura y aporta más seguridad a tu aplicación.

Conocer el Pentest Autónomo con IA →