Threats Feed
- Public
Espionage Operations by Flying Kitten Impact US, Israel, and Academia
The Flying Kitten group conducted extensive espionage and surveillance campaigns from 2013 to 2014. Utilizing spearphishing, social engineering, and the "Stealer" malware, they targeted high-profile individuals, security researchers, and various sectors. The campaigns involved compromised social media accounts and phishing domains to gather credentials and sensitive information. The malware recorded keystrokes, took screenshots, and collected system data, focusing on credential harvesting rather than file exfiltration. This activity impacted targets in the United States, Israel, and global academia and business sectors.
read more about Espionage Operations by Flying Kitten Impact US, Israel, and Academia - Public
Flying Kitten to Rocket Kitten: Persistent Phishing Threats from Iran
The Iranian cyber groups Flying Kitten and Rocket Kitten exhibited overlapping tactics in credential theft and spearphishing, targeting entities in sectors like media, education, and technology across the UK, US, and Iran. Utilizing domains that mimicked legitimate services, such as Google and Microsoft, they orchestrated phishing campaigns to harvest user credentials. Their operations involved shared phishing toolkits and malware, including a keylogger, with connections back to Iranian infrastructure. Despite cessation of Flying Kitten activities post-2014, their tools and tactics were resurrected by Rocket Kitten, highlighting the persistent threat posed by these actors.
read more about Flying Kitten to Rocket Kitten: Persistent Phishing Threats from Iran - Public
Iranian Ajax Security Team Conducts Espionage on U.S. Defense Contractors
FireEye's May 2014 Operation Saffron Rose report documents the Ajax Security Team's transition from website defacements (active 2010–2013) to malware-based espionage. The group used three parallel attack vectors: spearphishing emails impersonating the IEEE Aerospace Conference (aeroconf2014[.]org, registered under keyvan.ajaxtm@gmail.com, linking directly to Ajax Security Team leader "HUrr!c4nE!"); credential-phishing pages mimicking Outlook Web Access and VPN login portals targeting US defense industrial base companies; and trojanized anti-censorship software (Psiphon, Ultrasurf, Gerdoovpn, Proxifier) distributed to Iranian users and dissidents. The custom Stealer malware — a .NET dropper deploying IntelRS.exe and AppTransferWiz.dll — collected system info, performed keylogging, took screenshots, harvested browser credentials (Chrome, Firefox, Opera, IE), extracted IM account data (GTalk, Pidgin, Yahoo, Skype), and RDP credentials. Stolen data was AES-256 encrypted locally using the Persian passphrase "HavijeBaba" (salt: "salam!*%#") before FTP exfiltration to actor-controlled C2 infrastructure. FireEye recovered data from 77 victims on one C2 server — 44 had timezone set to "Iran Standard Time" and 37 also had Persian language settings, confirming the anti-censorship campaign targeted Iranian users inside Iran. The campaign's infrastructure linked three clusters via shared IPs, with the registration trail tracing directly to "HUrr!c4nE!" (aka k3yv4n), founder of the Ajax Security Team. The Stealer Builder (compiled 2014-04-08) allowed operators to configure custom C2 credentials and bind the backdoor to legitimate applications.
read more about Iranian Ajax Security Team Conducts Espionage on U.S. Defense Contractors - Public
Iranian FLYING KITTEN Targets U.S. Defense and Dissidents
CrowdStrike Intelligence tracked FLYING KITTEN — also known as Ajax Security Team — from mid-January 2014, identifying a combination of credential theft and malware delivery targeting multiple US-based defense contractors and political dissidents. The actor registered spoofed domains mimicking target organizations and hosted fake login pages to harvest credentials. After victims entered their credentials, they were redirected to a page prompting them to download a "Browser Patch" — which was actually the Stealer malware (PDB path: Stealer\obj\x86\Release\Stealer.pdb). Stealer exfiltrated captured data to an FTP server. The group also operated parmanpower[.]com, a fake recruiting website registered under the same email (info@usa.gov.us) as other FLYING KITTEN domains, likely used for broader credential collection. Earlier in 2014, FLYING KITTEN used a spoofed IEEE Aerospace Conference website (aeroconf2014[.]org) in the same manner. Attribution was aided by an operational security mistake: domains were initially registered under keyvan.ajaxtm@gmail.com, a Gmail address directly linking the operation to the Iran-based Ajax Security Team, before being updated to the usa.gov.us registrant email. CrowdStrike released YARA rules for both the Stealer RAT and the Flying Kitten installer (IntelRapidStart.exe) to assist in detection.
read more about Iranian FLYING KITTEN Targets U.S. Defense and Dissidents