Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Ajax Security Team

Also known as: Operation Woolen-Goldfish, AjaxTM, Rocket Kitten, Flying Kitten, Operation Saffron Rose, TEMP.Beanie, Saffron Rose, Ajax Security Team, Group 26, Operation Woolen Goldfish, Thamar Reservoir, Timberworm, SaffronRose, AjaxSecurityTeam, Sayad, Phosphorus, APT35, APT 35, Newscaster Team, Magic Hound, Mint Sandstorm, TA453, other aliases, ITG18, several other aliases, Shell Crew, WebMasters, KungFu Kittens, APT28, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Transparent Tribe, APT36, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, is a sophisticated, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Turla, Snake, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, Charming Kitten, Charming, Sandworm Team, Operation Cleaver, PinkPanther, a separate entity, VOLTZITE, for follow-on operations, the ALPHV Ransomware Group, ALPHV Blackcat, Jumpy Pisces, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Turbine Panda, Hippo Team, JerseyMikes, Cobalt Group, GOLD KINGSWOOD, COBALT SPIDER, G0080, Mule Libra

Description

Ajax Security Team (AST) emerged from the Iranian hacker community as a collective that initially engaged in defacing public websites under the moniker "AjaxTM" between 2010 and 2013. A transition to more covert operations was noted by 2014, when AST shifted focus toward malware‑based espionage targeting the U.S. defense industrial base and Iranian users employing anti‑censorship technologies. The actor’s toolkit is heavily custom‑developed, featuring FireMalv for browser credential extraction (particularly from Firefox), CWoolger and MPK for comprehensive keylogging, as well as Gholee/Wrapper for downloading secondary payloads. AST also demonstrates proficiency with PowerShell scripts and open‑source RATs such as Pupy to facilitate lateral movement and persistence. Operationally, AST relies on high‑precision social engineering. Spearphishing attachments, often in the form of Office documents or PDFs, are used to deliver malicious files that trigger user execution. In addition, the group exploits supply‑chain weaknesses by compromising third‑party web hosting services—an approach seen in campaigns such as Operation Woolen‑Goldfish and Thamar Reservoir—to host malware and C2 infrastructure on bulletproof or domain‑staged domains (e.g., TEMP.*, MagicHound.*). The organization’s persistence is reinforced through credential theft tools that harvest stored passwords, browser credentials, and account information. By combining these methods with network reconnaissance (account discovery, system info) AST can maintain backdoors within targeted environments, enabling extended espionage missions across a broad sector footprint.

TTP Summary

Supply-chain attacks such as strategic web compromise (SWC) where the actor compromise 3rd-party service provider hosting the victim websites

Goals & Targeting

Targeted Sectors

Defense
Energy
Media
Education
Research
Critical infrastructure
Government
Financial services
Telecommunications
Healthcare
Critical infrastructure
Manufacturing
Non profit
Pharmaceutical
Aviation
Hospitality
Aerospace
Think tank
Retail
Gaming
Transportation
Information technology
Legal services
Mining
Chemical
Maritime
Utilities
Nuclear
Entertainment
Oil gas
Construction
Aerospace & defense
Legal

Targeted Countries / Regions

IL
IR
SA
US
CN
RU
VN
IN
JP
PK
UA
GB
AU
KR
TW
AE
KP
SG
DE
TR
BY
BR
MX
ES
PL
CA
RO
FR
NG
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· 57 minutes ago

Executive Summary

Ajax Security Team, also known by aliases such as Rocket Kitten and Magic Hound, is an Iran‑based APT that evolved from website defacement in 2010 to sophisticated malware‑driven espionage against U.S. defense contractors and Iranian anti‑censorship users by 2014. The group leverages spearphishing, supply‑chain attacks via compromised third‑party hosting, and custom tools—including FireMalv, CWoolger, Gholee/Wrapper, and MPK—to plant keyloggers and credential stealers while maintaining persistent access.

Goals & Targeting

AST primarily targets entities involved in defense, energy, telecommunications, and technology—industries that hold strategic information for both the United States and Iran. The group’s objectives include gathering sensitive technical data on U.S. defense contractors, probing adversary supply chains, and undermining Iranian dissident support by compromising anti‑censorship tools. Victims are typically mid‑ to large‑scale enterprises with exposed web assets or those engaged in geopolitical conflicts, allowing AST to harvest intellectual property and elevate its strategic leverage for Iran‑state interests.

Enhanced Description

Key Capabilities

  • Custom malware development (FireMalv, CWoolger, Gholee/Wrapper, MPK)
  • Keylogging and credential harvesting from browsers
  • Supply‑chain compromise via third‑party web hosting
  • Spearphishing attachment delivery with social engineering
  • Persistent access through backdoor RATs (Pupy, custom scripts)
  • Use of PowerShell for execution and download tasks
  • Credential discovery and password dump from local stores or web browsers

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Discovery
Command and Control
Exfiltration

ATT&CK Techniques

T1566.001
T1566.003
T1204
T1204.002
T1059.001
T1055
T1071
T1087
T1105
T1555
T1555.003
T1056.001

Software / Tooling

FireMalv
CWoolger
Gholee/Wrapper
MPK
Pupy
PowerShell scripts
Custom RATs

Campaigns & Victims

AST’s campaign pattern illustrates a blend of targeted spearphishing and supply‑chain compromise. Notable operations—Operation Woolen‐Goldfish, Thamar Reservoir, and the Magic Hound campaigns—demonstrated recurring use of domain names prefixed with "TEMP." or "MagicHound." The group maintains an operational tempo that allows repeated exploitation of defense contractors while also probing Iranian anti‑censorship user communities. Historical data shows a consistent focus on sectors defined in the actor’s known target list, indicating both strategic intelligence gathering and influence operations. The overlapping aliases with other APTs (e.g., APT35, Charming Kitten) suggest either shared infrastructure or a fluid attribution approach common to Iranian state‑aligned actors. However, forensic evidence from malware analysis, spearphishing artifacts, and supply‑chain compromise incidents strongly supports AST’s identity as a distinct threat actor. Despite limited recent activity reporting, the persistence of its custom toolset suggests continued operational capability.

IOC Patterns

  • Spear-phishing attachment with malicious Office document or PDF

Recommended Actions

  • Deploy advanced email filtering and sandboxing to block spearphishing attachments
  • Implement endpoint detection & response tuned for keyloggers and credential dumper signatures (FireMalv, CWoolger)
  • Verify integrity of third‑party web hosting and monitor DNS activity for domain names resembling "TEMP.*" or "MagicHound.*"
  • Enforce least privilege and network segmentation to limit lateral movement
  • Regular patching of operating systems and web application platforms to close known vulnerabilities used by the group

Suggested Tags

APT
Iran-based
Espionage
Supply-Chain Attack
Defacement
Spearphishing
Keylogging
Credential Theft
Defense Contractors
Energy Sector
Anti-Censorship Tools

Confidence Assessment

Moderate confidence. The core facts—active since 2010, Iranian origin, transition to espionage, use of custom malware (FireMalv, CWoolger), and supply‑chain compromise techniques—are corroborated by multiple independent reports from FireEye (Saffron Rose), CrowdStrike (Firing Kitten), and Secureworks (Magic Hound). Ambiguities remain regarding the degree of operational overlap with other Iranian APTs (e.g., APT35/Cherishing Kitten) due to shared aliases, and current activity beyond 2015 is not well documented.

ATT&CK Techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 11 IPv4 Address 1 SHA-256 Hash 6 Filename 2

References

  1. TrendMicro Operation Woolen Goldfish March 2015 — Cedric Pernet, Kenney Lu. (2015, March 19). Operation Woolen-Goldfish - When Kittens Go phishing. Retrieved April 21, 2021.
  2. Check Point Rocket Kitten — Check Point Software Technologies. (2015). ROCKET KITTEN: A CAMPAIGN WITH 9 LIVES. Retrieved March 16, 2018.
  3. CrowdStrike Flying Kitten — Dahl, M.. (2014, May 13). Cat Scratch Fever: CrowdStrike Tracks Newly Reported Iranian Actor as FLYING KITTEN. Retrieved May 27, 2020.
  4. IranThreats Kittens Dec 2017 — Iran Threats . (2017, December 5). Flying Kitten to Rocket Kitten, A Case of Ambiguity and Shared Code. Retrieved May 28, 2020.
  5. FireEye Operation Saffron Rose 2013 — Villeneuve, N. et al.. (2013). OPERATION SAFFRON ROSE . Retrieved May 28, 2020.
  6. www.huntress.com — Cited by web research for: other aliases
  7. attack.mitre.org — Cited by web research for: APT28
  8. attack.mitre.org — Cited by web research for: T1555
  9. unit42.paloaltonetworks.com — Cited by web research for: Leash
  10. https://www.fireeye.com/current-threats/operation-saffron-rose.html — Cited by AI analysis.
  11. https://www.crowdstrike.com/blog/research/rocket-kitten-spear-phishing-attack/ — Cited by AI analysis.
  12. https://secureworks.com/research/magic-hound-attack — Cited by AI analysis.

Intel Summary

14

Techniques

64

Tools

2

Campaigns

40

IOCs

0

Observed Data

7

Tactics

Tags

APT
espionage
defense-sector
energy-sector
Iran-based
Espionage
Supply-Chain Attack
Defacement
Spearphishing
Keylogging
Credential Theft
Defense Contractors
Energy Sector
Anti-Censorship Tools

Details

MITRE ID
G0130
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
Iran (IR)
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--fa19de15-6169-428d-9cd6-3ca3d56075b7
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.