Ajax Security Team — APT Profile

Ajax Security Team is an Iran-based group that emerged around 2010 out of the Persian-language defacement scene surrounding the Ashiyane and Shabgard forums, and by 2014 had shifted to malware-based espionage. FireEye's Operation Saffron Rose report documented spearphishing and spoofed Outlook Web Access and VPN portals used against the US defense industrial base and against Iranian users of anti-censorship tools, delivering a non-public implant FireEye called Stealer. FireEye assessed that the group's activities appeared to align with Iranian government political objectives but stated it was "unclear whether the Ajax Security Team operates in isolation or if they are a part of a larger coordinated effort on the part of the Iranian government." Vendor naming is contested: CrowdStrike tracks this activity as FLYING KITTEN and ties it to the Ajax Security Team, an Iranian information security company, while MITRE additionally lists Rocket Kitten and Operation Woolen-Goldfish on the basis of a stated "potential relationship" in infrastructure and tooling — a link CrowdStrike does not adopt, keeping ROCKET KITTEN as a separate IRGC-nexus adversary active since 2014.

Also tracked as

Operation Woolen-Goldfish, AjaxTM, Rocket Kitten, Flying Kitten, Operation Saffron Rose, SaffronRose, Sayad, TEMP.Beanie, Thamar Reservoir, Timberworm, G0130

IntelFusions coverage (1)

Tools & malware

Vendor research

Read the full analysis on IntelFusions