For years, the low-skilled TA2541 group has been using malware in malicious campaigns targeting companies in the aviation sector as well as other sensitive industries.

See also: Sports brand Mizuno falls victim to ransomware attack
The threat actor has been active since at least 2017, targeting entities in the aviation, aerospace, transportation, manufacturing, and defense industries.
The TA2541 group (as cybersecurity firm Proofpoint has named it), is believed to operate from Nigeria and its activity has been documented in the past in analysis of separate campaigns.
Unsophisticated attacks
In a report today, Proofpoint notes that the TA2541 threat actor was consistent in its attack method, relying on malicious Microsoft Word documents to deliver a remote access tool (RAT).
A typical malware campaign from this group involves sending “hundreds to thousands” of emails – mostly in English – to “hundreds of organizations worldwide, with recurring targets in North America, Europe and the Middle East.”.
See also: Ukraine: Says it is the target of a "massive wave of hybrid warfare"
Recently, however, the group has switched from malicious attachments to linking to a payload hosted on cloud services like Google Drive, Proofpoint researchers say.
The TA2541 group does not use custom malware, but rather commodity malicious tools available for purchase on cybercrime forums. According to the researcher's observations, AsyncRAT, NetWire, WSH RAT, and Parallax appear to be the group's favorites that are most frequently promoted in malicious messages.
Proofpoint highlights that the malware used in TA2541 campaigns can be used for intelligence gathering, but the ultimate goal of the threat actor currently remains unknown.
A typical TA2541 attack chain starts by sending an email that is usually related to transportation and delivers a malicious document.

In the next step, it runs PowerShell in various Windows processes and searches for available security products by querying Windows Management Instrumentation (WMI).
It then attempts to disable built-in defenses and begins collecting system information before downloading the RAT payload to the compromised host.
See also: BlackCat: Claimed responsibility for the ransomware attack on Swissport
Given TA2541's choice of targets, its activity did not go unnoticed, and security researchers from other companies have analyzed its campaigns in the past, but without connecting all the evidence.
Cisco Talos published a report last year about a TA2541 campaign targeting the airline industry with AsyncRAT. Researchers concluded that the threat actor had been active for at least five years.
Based on evidence from the analysis of the infrastructure used in the attack, Cisco Talos was able to create a profile for the threat actor, linking its geographical location to Nigeria.
Even though TA2541's tactics, techniques, and procedures (TTPs) describe someone who is not technically sophisticated, the threat actor managed to develop malicious campaigns for more than five years without attracting much attention.
Information source: bleepingcomputer.com
