THREAT_ACTOR · G0130
Ajax Security Team
Also known as: Ajax Security Team, Operation Woolen-Goldfish, AjaxTM, Rocket Kitten, Flying Kitten, Operation Saffron Rose
Profile
Ajax Security Team is a group that has been active since at least 2010 and believed to be operating out of Iran. By 2014 Ajax Security Team transitioned from website defacement operations to malware-based cyber espionage campaigns targeting the US defense industrial base and Iranian users of anti-censorship technologies.
MITRE ATT&CK ↗Techniques
6 ATT&CK techniques attributed to this actor.
Software
2 malware/tools attributed to this actor.
Related corpus activity
9,077 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Ajax Security Team.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2026-3844 | cve | — | 85 | 1 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2026-0740 | cve | — | 85 | 1 |
| cve-2023-52271 | cve | ransomware | 85 | 3 |
| cve-2025-7852 | cve | — | 85 | 1 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-7443 | cve | — | 85 | 1 |
| cve-2025-61155 | cve | ransomware | 85 | 3 |
| cve-2017-17215 | cve | — | 85 | 2 |
| cve-2025-1055 | cve | ransomware | 85 | 3 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2025-12057 | cve | — | 85 | 1 |
| cve-2025-34085 | cve | — | 85 | 1 |
| 669002654c264191d4660fbf757860d930175649735f81370b9f1af3658a304c | sha256 | phishing | 80 | 2 |
| d35695f2366a43628231e73ffa83ca106306a8fa | hash | — | 80 | 2 |
| 82e579bd49d69845133c9aa8585f8bd26736437b | hash | — | 80 | 2 |
| 60972abf5425c191c81bae117f1dedaea13d39bc52f367d5dff9ad1aa4b9c5ca | sha256 | phishing | 80 | 2 |
| 62a879b0d1c1649cc72b2b6f61a8f6bd888625ce6e8a7aefe0a0461e4f27c525 | sha256 | phishing | 80 | 2 |
| 107b5aa3c4ef30b9b832e0a10b1efb1dcf433158bc6af8d890d66c0c9ed50d21 | sha256 | — | 80 | 1 |
Showing the top 30 by severity of 9,077.