Ajax Security Team
Also known as: Operation Woolen-Goldfish · AjaxTM · Rocket Kitten · Flying Kitten · Operation Saffron Rose
Overview
Ajax Security Team is a group that has been active since at least 2010 and believed to be operating out of Iran. By 2014 Ajax Security Team transitioned from website defacement operations to malware-based cyber espionage campaigns targeting the US defense industrial base and Iranian users of anti-censorship technologies.
Naming & attribution
Ajax Security Team is tracked under 6 names across the industry. It uses 6 documented ATT&CK techniques — more than 17% of the 174 groups tracked here. Activity attributed since at least 2010.
| Name | First reported by |
|---|---|
| Operation Woolen-Goldfish | Check Point Software Technologies |
| AjaxTM | Villeneuve, N. et al. |
| Rocket Kitten | Check Point Software Technologies |
| Operation Saffron Rose | Villeneuve, N. et al. |
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- PLATINUM — 4 shared techniques (31% overlap)
- IndigoZebra China — 3 shared techniques (30% overlap)
- Nomadic Octopus Russia — 3 shared techniques (30% overlap)
- Elderwood China — 3 shared techniques (25% overlap)
- Rancor — 3 shared techniques (25% overlap)
- Tonto Team China — 4 shared techniques (24% overlap)
Targets
Activists · Aerospace · Civil society · Defense · Education · Gas · Government · Journalists · Military · Oil · Research - Innovation
Regions
Afghanistan · Canada · Egypt · Iran · Iranian internet activists · Iraq · Israel · Jordan · Kuwait · Saudi Arabia · Syria · Turkey · United Arab Emirates · United Kingdom · United States · Venezuela · Yemen
TTPs — 6 techniques across 5 tactics
Initial Access
-
T1566.001Spearphishing Attachment -
T1566.003Spearphishing via Service
Execution
-
T1204.002Malicious File
Credential Access
-
T1555.003Credentials from Web Browsers
Collection
-
T1056.001Keylogging
Command and Control
-
T1105Ingress Tool Transfer
Tools & malware (2)
sqlmap · Havij
Reporting (3)
- Flying Kitten to Rocket Kitten, A Case of Ambiguity and Shared Code — Iran Threats
- Operation Woolen-Goldfish - When Kittens Go phishing — Cedric Pernet, Kenney Lu
- ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES — Check Point Software Technologies