Actors Insights|Latest update04/07/2026

Ajax Security Team

Named by FireEyeSuspected state sponsor: Islamic Republic of Iran

Ajax Security Team is the hacktivist identity and origin name of the Iranian threat cluster known as Flying Kitten. Beginning around 2010, the group operated as a defacement-focused collective on Iranian hacker forums before transitioning to targeted espionage campaigns against US defense contractors and Iranian dissidents. FireEye tracked the group's evolution from opportunistic website defacements to sophisticated spear phishing and malware distribution operations. Ajax Security Team members were identified through their activity on Ashiyane and similar Iranian hacking forums, providing a documented link between Iran's hacktivist community and state-directed cyber operations.

First Seen:Mar 2013
Last Seen:Sep 2019
Indexed Reports:1
Public IOCs:38
also known as:
SaffronRoseAjaxSecurityTeamGroup 26 (Talos)SayadFlying Kitten (CrowdStrike)Operation Woolen-GoldfishAjaxTMRocket Kitten (CrowdStrike)Operation Saffron RoseG0130 (Mitre)

Targeted Regions

Iran
IR
Iran
Iran
Oct 2013 ~ May 2014
Oct 2013 ~ May 2014
United States
US
United States
United States
Oct 2013 ~ May 2014
Oct 2013 ~ May 2014
Jan 2013Jun 2026

Targeted Sectors

DefenseDissidentAerospace

Disclaimer: We are working on indexing and analyzing relevant data and this process is not fully completed yet. Therefore, displayed details and statistics may will change in the future.