Iranian Ajax Security Team Conducts Espionage on U.S. Defense Contractors
- Actor Motivations: Espionage,Exfiltration
- Attack Vectors: Credential stuffing,Spyware,Spear Phishing
- Attack Complexity: Medium
- Threat Risk: High Impact/Low Probability
Threat Overview
FireEye's May 2014 Operation Saffron Rose report documents the Ajax Security Team's transition from website defacements (active 2010–2013) to malware-based espionage. The group used three parallel attack vectors: spearphishing emails impersonating the IEEE Aerospace Conference (aeroconf2014[.]org, registered under keyvan.ajaxtm@gmail.com, linking directly to Ajax Security Team leader "HUrr!c4nE!"); credential-phishing pages mimicking Outlook Web Access and VPN login portals targeting US defense industrial base companies; and trojanized anti-censorship software (Psiphon, Ultrasurf, Gerdoovpn, Proxifier) distributed to Iranian users and dissidents. The custom Stealer malware — a .NET dropper deploying IntelRS.exe and AppTransferWiz.dll — collected system info, performed keylogging, took screenshots, harvested browser credentials (Chrome, Firefox, Opera, IE), extracted IM account data (GTalk, Pidgin, Yahoo, Skype), and RDP credentials. Stolen data was AES-256 encrypted locally using the Persian passphrase "HavijeBaba" (salt: "salam!*%#") before FTP exfiltration to actor-controlled C2 infrastructure. FireEye recovered data from 77 victims on one C2 server — 44 had timezone set to "Iran Standard Time" and 37 also had Persian language settings, confirming the anti-censorship campaign targeted Iranian users inside Iran. The campaign's infrastructure linked three clusters via shared IPs, with the registration trail tracing directly to "HUrr!c4nE!" (aka k3yv4n), founder of the Ajax Security Team. The Stealer Builder (compiled 2014-04-08) allowed operators to configure custom C2 credentials and bind the backdoor to legitimate applications.
Detected Targets
| Type | Description | Confidence |
|---|---|---|
| Sector | Defense | Verified |
| Sector | Dissident None | Verified |
| Sector | Aerospace | Verified |
| Region | Iran | Verified |
| Region | United States | Verified |
Extracted IOCs
- accounts-apple[.]com
- aeroconf2014[.]org
- ajaxtm[.]org
- appleid.com[.]co
- intel-update[.]com
- loginz[.]me
- mailservermigration[.]tk
- plugin-adobe[.]com
- privacy-google[.]com
- ultrasms[.]ir
- update-mirror[.]com
- users-facebook[.]com
- vpnsecurityverification[.]tk
- webpanelpages[.]tk
- xn--facebook-06k[.]com
- xn--google-yri[.]com
- yahoomail.com[.]co
- ns2.aeroconf2014[.]org
- office.windows-essentials[.]tk
- invite@aeroconf2014[.]org
- james.mateo@aim[.]com
- keyvan.ajaxtm@gmail[.]com
- lvlr98@gmail[.]com
- osshom@yahoo[.]com
- 1823b77b9ee6296a8b997ffb64d32d21
- 1d4d9f6e6fa1a07cb0a66a9ee06d624a
- 288c91d6c0197e99b92c06496921bf2f
- 3d26442f06b34df3d5921f89bf680ee9
- 3efd971db6fbae08e96535478888cff9
- 6dc7cc33a3cdcfee6c4edb6c085b869d
- 5156aca994ecfcb40458ead8c830cd66469d5f5a031392898d323a8d7a7f23d3
- 5[.]9.244.151
- 81[.]17.28.227
- 81[.]17.28.229
- 81[.]17.28.231
- 81[.]17.28.235
- 88[.]150.227.197
Tip: 37 related IOCs (6 IP, 19 domain, 0 URL, 5 email, 7 file hash) to this threat have been found.
Overlaps
Source: Iran Threats - February 2018
Detection (seven cases): 88[.]150.227.197, lvlr98@gmail[.]com, osshom@yahoo[.]com, ultrasms[.]ir, users-facebook[.]com, xn--facebook-06k[.]com, xn--google-yri[.]com
Source: Crowdstrike - May 2014
Detection (one case): aeroconf2014[.]org
Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.
FAQs
Frequently Asked Questions about Operation Saffron Rose
FireEye's Operation Saffron Rose report documented the Ajax Security Team — an Iranian hacking group — running a dual-track espionage campaign in late 2013 and early 2014. On one track, they targeted US defense contractors using spearphishing emails impersonating the IEEE Aerospace Conference and fake login pages for Outlook Web Access and VPN portals. On the other, they distributed trojanized versions of anti-censorship software (Psiphon, Ultrasurf) to Iranian users and dissidents inside Iran. Both tracks used the same custom Stealer malware to harvest credentials, log keystrokes, take screenshots, and exfiltrate stolen data to attacker-controlled servers.
The Ajax Security Team was an Iranian hacking group formed around 2010 by members known as "HUrr!c4nE!" (aka k3yv4n) and "Cair3x." The group initially engaged in website defacements and exploit releases on Iranian hacker forums, before becoming increasingly political and transitioning to cyber espionage by late 2013. FireEye directly linked the espionage campaign to "HUrr!c4nE!" through a registration trail: the attack domain aeroconf2014[.]org was initially registered under keyvan.ajaxtm@gmail.com — the same email used to register ajaxtm[.]org, the Ajax Security Team's own website. The group is assessed to have links to Iranian state interests, consistent with the Basij Cyber Council model of recruiting hackers for intelligence operations.
The campaign pursued two parallel goals. Against US defense contractors, the goal was intelligence collection — stealing credentials and sensitive data from companies in the defense industrial base. Against Iranian users, the goal was surveillance and counter-dissidence: by distributing trojanized anti-censorship tools, the group could monitor Iranians who were trying to bypass the government's internet filtering system, identifying activists and dissidents. FireEye recovered data from 77 victims on one C2 server, the majority of whom had Iranian timezone and Persian language settings — confirming the domestic surveillance intent.
The campaign had two distinct target groups. The first was US defense industrial base companies — particularly those connected to the aerospace and defense sectors, targeted through the fake IEEE Aerospace Conference lure and spoofed corporate login pages. The second was Iranian users of anti-censorship software and dissidents — people inside Iran or in the diaspora who were using tools like Psiphon and Ultrasurf to bypass the Iranian government's internet filtering system. These two groups represent very different intelligence priorities: foreign defense intelligence on one side, domestic dissidence monitoring on the other.
The Ajax Security Team used three methods simultaneously. First, spearphishing emails from a fake IEEE Aerospace Conference domain directed defense contractor employees to install "proxy" software — which was actually the Stealer malware. Second, fake Outlook Web Access and VPN login pages tailored to specific defense companies captured real credentials, giving the attackers legitimate network access. Third, trojanized versions of legitimate anti-censorship tools (Psiphon, Ultrasurf, Gerdoovpn, Proxifier) were distributed to Iranian users — the malware was hidden inside the real installer, so users got the working software and the Stealer backdoor simultaneously. All three methods delivered the same Stealer payload, which collected everything from keystrokes and screenshots to browser credentials, IM accounts, and RDP passwords, encrypting it all before sending it to the attackers' FTP servers.
The Stealer malware was a custom-built tool the Ajax Security Team called simply "Stealer." Once installed, it ran silently in the background and collected: system information (hostname, IP addresses, open ports, running processes, installed applications, timezone), keystrokes, periodic screenshots, credentials and history from Chrome, Firefox, Opera, and Internet Explorer, instant messaging account data from GTalk, Pidgin, Yahoo, and Skype, RDP account credentials from the Windows vault, and configuration details from any proxy software installed. All collected data was encrypted locally using AES-256 with a Persian passphrase ("HavijeBaba") before being transmitted to attacker-controlled FTP servers. The use of Persian language words in the encryption key is one of several indicators pointing to the Iranian origins of the malware's developers.
US defense contractors hold sensitive information about weapons programs, military technology, and defense contracts that is directly valuable to Iranian intelligence. The aerospace sector was specifically targeted through the fake IEEE Aerospace Conference lure, suggesting the attackers had good knowledge of which events defense industry professionals attend. Iranian anti-censorship users are targeted for a different reason: the Iranian government actively monitors and suppresses those who circumvent its internet filtering system, viewing them as political threats. By trojanizing popular tools like Psiphon and Ultrasurf, the Ajax Security Team could identify who inside Iran was trying to access blocked content — and by extension, who might be a dissident, activist, or opposition figure worth monitoring.
Defense contractor employees should be cautious about any email inviting them to install software to access a conference website — legitimate academic and industry conferences do not require proxy software installation. Verify conference domains carefully: the real IEEE Aerospace Conference is at aeroconf.org, not variations like aeroconf2014[.]org. Only access corporate Outlook Web Access or VPN portals via bookmarked, verified URLs — never via links in emails. For Iranian users and dissidents: only download Psiphon, Ultrasurf, and similar tools from their official verified websites, and check file hashes before running any installer. Monitor endpoints for IntelRS.exe, AppTransferWiz.dll, or RapidStartTech.stl files appearing in AppData directories. Block the known C2 domains and IPs: aeroconf2014[.]org, intel-update[.]com, update-mirror[.]com, plugin-adobe[.]com, ultrasms[.]ir, and 88.150.227.197, 5.9.244.151, and the 81.17.28.x IP range.