Flying Kitten, Ajax Security Team Archived: 2026-04-05 12:59:32 UTC Home > List all groups > Flying Kitten, Ajax Security Team APT group: Flying Kitten, Ajax Security Team Names Flying Kitten (CrowdStrike) Ajax Security Team (FireEye) Group 26 (Talos) G0130 (MITRE) Country Iran Sponsor State-sponsored Motivation Information theft and espionage First seen 2010 Description (FireEye) Members of this group have accounts on popular Iranian hacker forums such as ashiyane[.]org and shabgard[.]org, and they have engaged in website defacements under the group name “AjaxTM” since 2010. By 2014, the Ajax Security Team had transitioned from performing defacements (their last defacement was in December 2013) to malware-based espionage, using a methodology consistent with other advanced persistent threat actors in this region. (Crowdstrike) CrowdStrike Intelligence has also been tracking and reporting internally on this threat group since mid-January 2014 under the name FLYING KITTEN, and since that time has seen targeting of multiple U.S.-based defense contractors as well as political dissidents. Observed Sectors: Defense and dissidents. Countries: USA. Tools used Stealer. Operations performed 2013 Operation “Saffron Rose” Information https://apt.etda.or.th/cgi-bin/showcard.cgi?u=9d17cae3-0777-428b-b9b7-fcbdf52af5ba Page 1 of 2 MITRE ATT&CK Last change to this card: 16 August 2025 Download this actor card in PDF or JSON format Source: https://apt.etda.or.th/cgi-bin/showcard.cgi?u=9d17cae3-0777-428b-b9b7-fcbdf52af5ba https://apt.etda.or.th/cgi-bin/showcard.cgi?u=9d17cae3-0777-428b-b9b7-fcbdf52af5ba Page 2 of 2