Also known as: Operation Woolen-Goldfish, AjaxTM, Rocket Kitten, Flying Kitten, Operation Saffron Rose, TEMP.Beanie, Saffron Rose, Ajax Security Team, Group 26, Operation Woolen Goldfish, Thamar Reservoir, Timberworm, SaffronRose, AjaxSecurityTeam, Sayad, Phosphorus, APT35, APT 35, Newscaster Team, Magic Hound, Mint Sandstorm, TA453, other aliases, ITG18, several other aliases, Shell Crew, WebMasters, KungFu Kittens, APT28, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Transparent Tribe, APT36, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Turla, Snake, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, Charming Kitten, Charming, Sandworm Team, Operation Cleaver, PinkPanther, a separate entity, VOLTZITE, for follow-on operations, the ALPHV Ransomware Group, ALPHV Blackcat, Jumpy Pisces, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Turbine Panda, Hippo Team, JerseyMikes, Cobalt Group, GOLD KINGSWOOD, COBALT SPIDER, G0080, Mule Libra
Ajax Security Team (AST) emerged from the Iranian hacker community as a collective that initially engaged in defacing public websites under the moniker "AjaxTM" between 2010 and 2013. A transition to more covert operations was noted by 2014, when AST shifted focus toward malware‑based espionage targeting the U.S. defense industrial base and Iranian users employing anti‑censorship technologies. The actor’s toolkit is heavily custom‑developed, featuring FireMalv for browser credential extraction (particularly from Firefox), CWoolger and MPK for comprehensive keylogging, as well as Gholee/Wrapper for downloading secondary payloads. AST also demonstrates proficiency with PowerShell scripts and open‑source RATs such as Pupy to facilitate lateral movement and persistence. Operationally, AST relies on high‑precision social engineering. Spearphishing attachments, often in the form of Office documents or PDFs, are used to deliver malicious files that trigger user execution. In addition, the group exploits supply‑chain weaknesses by compromising third‑party web hosting services—an approach seen in campaigns such as Operation Woolen‑Goldfish and Thamar Reservoir—to host malware and C2 infrastructure on bulletproof or domain‑staged domains (e.g., TEMP.*, MagicHound.*). The organization’s persistence is reinforced through credential theft tools that harvest stored passwords, browser credentials, and account information. By combining these methods with network reconnaissance (account discovery, system info) AST can maintain backdoors within targeted environments, enabling extended espionage missions across a broad sector footprint.
Supply-chain attacks such as strategic web compromise (SWC) where the actor compromise 3rd-party service provider hosting the victim websites
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Ajax Security Team, also known by aliases such as Rocket Kitten and Magic Hound, is an Iran‑based APT that evolved from website defacement in 2010 to sophisticated malware‑driven espionage against U.S. defense contractors and Iranian anti‑censorship users by 2014. The group leverages spearphishing, supply‑chain attacks via compromised third‑party hosting, and custom tools—including FireMalv, CWoolger, Gholee/Wrapper, and MPK—to plant keyloggers and credential stealers while maintaining persistent access.
Goals & Targeting
AST primarily targets entities involved in defense, energy, telecommunications, and technology—industries that hold strategic information for both the United States and Iran. The group’s objectives include gathering sensitive technical data on U.S. defense contractors, probing adversary supply chains, and undermining Iranian dissident support by compromising anti‑censorship tools. Victims are typically mid‑ to large‑scale enterprises with exposed web assets or those engaged in geopolitical conflicts, allowing AST to harvest intellectual property and elevate its strategic leverage for Iran‑state interests.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
AST’s campaign pattern illustrates a blend of targeted spearphishing and supply‑chain compromise. Notable operations—Operation Woolen‐Goldfish, Thamar Reservoir, and the Magic Hound campaigns—demonstrated recurring use of domain names prefixed with "TEMP." or "MagicHound." The group maintains an operational tempo that allows repeated exploitation of defense contractors while also probing Iranian anti‑censorship user communities. Historical data shows a consistent focus on sectors defined in the actor’s known target list, indicating both strategic intelligence gathering and influence operations. The overlapping aliases with other APTs (e.g., APT35, Charming Kitten) suggest either shared infrastructure or a fluid attribution approach common to Iranian state‑aligned actors. However, forensic evidence from malware analysis, spearphishing artifacts, and supply‑chain compromise incidents strongly supports AST’s identity as a distinct threat actor. Despite limited recent activity reporting, the persistence of its custom toolset suggests continued operational capability.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence. The core facts—active since 2010, Iranian origin, transition to espionage, use of custom malware (FireMalv, CWoolger), and supply‑chain compromise techniques—are corroborated by multiple independent reports from FireEye (Saffron Rose), CrowdStrike (Firing Kitten), and Secureworks (Magic Hound). Ambiguities remain regarding the degree of operational overlap with other Iranian APTs (e.g., APT35/Cherishing Kitten) due to shared aliases, and current activity beyond 2015 is not well documented.
Woolen Goldfish
Thamar Reservoir
No observed data linked yet.
14
Techniques
64
Tools
2
Campaigns
40
IOCs
0
Observed Data
7
Tactics