Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: Operation Woolen-Goldfish, AjaxTM, Rocket Kitten, Flying Kitten, Operation Saffron Rose
6
techniques
2
software
10,187
corpus matches
profile
Ajax Security Team is a group that has been active since at least 2010 and believed to be operating out of Iran. By 2014 Ajax Security Team transitioned from website defacement operations to malware-based cyber espionage campaigns targeting the US defense industrial base and Iranian users of anti-censorship technologies.
techniques
6 attributed · most-instrumented first
software
2 malware & tools attributed
Havij
S0224
sqlmap
S0225
read this carefully
10,187 corpus matches is not attribution
That count is indicators which exhibit techniques Ajax Security Team is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
credential-access
showing 30 of 10,187
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.