FORENSIA

THREAT_ACTOR · G0130

Ajax Security Team

Also known as: Ajax Security Team, Operation Woolen-Goldfish, AjaxTM, Rocket Kitten, Flying Kitten, Operation Saffron Rose

Profile

Ajax Security Team is a group that has been active since at least 2010 and believed to be operating out of Iran. By 2014 Ajax Security Team transitioned from website defacement operations to malware-based cyber espionage campaigns targeting the US defense industrial base and Iranian users of anti-censorship technologies.

MITRE ATT&CK ↗

Techniques

6 ATT&CK techniques attributed to this actor.

Software

2 malware/tools attributed to this actor.

Havijsqlmap

Related corpus activity

9,077 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Ajax Security Team.