Latest Update27/08/2026

Threats Feed

  1. Public

    Espionage Operations by Flying Kitten Impact US, Israel, and Academia

    The Flying Kitten group conducted extensive espionage and surveillance campaigns from 2013 to 2014. Utilizing spearphishing, social engineering, and the "Stealer" malware, they targeted high-profile individuals, security researchers, and various sectors. The campaigns involved compromised social media accounts and phishing domains to gather credentials and sensitive information. The malware recorded keystrokes, took screenshots, and collected system data, focusing on credential harvesting rather than file exfiltration. This activity impacted targets in the United States, Israel, and global academia and business sectors.

    read more about Espionage Operations by Flying Kitten Impact US, Israel, and Academia
  2. Public

    Flying Kitten to Rocket Kitten: Persistent Phishing Threats from Iran

    The Iranian cyber groups Flying Kitten and Rocket Kitten exhibited overlapping tactics in credential theft and spearphishing, targeting entities in sectors like media, education, and technology across the UK, US, and Iran. Utilizing domains that mimicked legitimate services, such as Google and Microsoft, they orchestrated phishing campaigns to harvest user credentials. Their operations involved shared phishing toolkits and malware, including a keylogger, with connections back to Iranian infrastructure. Despite cessation of Flying Kitten activities post-2014, their tools and tactics were resurrected by Rocket Kitten, highlighting the persistent threat posed by these actors.

    read more about Flying Kitten to Rocket Kitten: Persistent Phishing Threats from Iran
  3. Public

    Iranian FLYING KITTEN Targets U.S. Defense and Dissidents

    CrowdStrike Intelligence tracked FLYING KITTEN — also known as Ajax Security Team — from mid-January 2014, identifying a combination of credential theft and malware delivery targeting multiple US-based defense contractors and political dissidents. The actor registered spoofed domains mimicking target organizations and hosted fake login pages to harvest credentials. After victims entered their credentials, they were redirected to a page prompting them to download a "Browser Patch" — which was actually the Stealer malware (PDB path: Stealer\obj\x86\Release\Stealer.pdb). Stealer exfiltrated captured data to an FTP server. The group also operated parmanpower[.]com, a fake recruiting website registered under the same email (info@usa.gov.us) as other FLYING KITTEN domains, likely used for broader credential collection. Earlier in 2014, FLYING KITTEN used a spoofed IEEE Aerospace Conference website (aeroconf2014[.]org) in the same manner. Attribution was aided by an operational security mistake: domains were initially registered under keyvan.ajaxtm@gmail.com, a Gmail address directly linking the operation to the Iran-based Ajax Security Team, before being updated to the usa.gov.us registrant email. CrowdStrike released YARA rules for both the Stealer RAT and the Flying Kitten installer (IntelRapidStart.exe) to assist in detection.

    read more about Iranian FLYING KITTEN Targets U.S. Defense and Dissidents