Threats Feed|Flying Kitten|Last Updated 30/04/2026|AuthorCertfa Radar|Publish Date13/05/2014

Iranian FLYING KITTEN Targets U.S. Defense and Dissidents

  • Actor Motivations: Espionage,Exfiltration
  • Attack Vectors: Credential stuffing,Spyware,Spear Phishing
  • Attack Complexity: Medium
  • Threat Risk: High Impact/Low Probability

Threat Overview

CrowdStrike Intelligence tracked FLYING KITTEN — also known as Ajax Security Team — from mid-January 2014, identifying a combination of credential theft and malware delivery targeting multiple US-based defense contractors and political dissidents. The actor registered spoofed domains mimicking target organizations and hosted fake login pages to harvest credentials. After victims entered their credentials, they were redirected to a page prompting them to download a "Browser Patch" — which was actually the Stealer malware (PDB path: Stealer\obj\x86\Release\Stealer.pdb). Stealer exfiltrated captured data to an FTP server. The group also operated parmanpower[.]com, a fake recruiting website registered under the same email (info@usa.gov.us) as other FLYING KITTEN domains, likely used for broader credential collection. Earlier in 2014, FLYING KITTEN used a spoofed IEEE Aerospace Conference website (aeroconf2014[.]org) in the same manner. Attribution was aided by an operational security mistake: domains were initially registered under keyvan.ajaxtm@gmail.com, a Gmail address directly linking the operation to the Iran-based Ajax Security Team, before being updated to the usa.gov.us registrant email. CrowdStrike released YARA rules for both the Stealer RAT and the Flying Kitten installer (IntelRapidStart.exe) to assist in detection.

Detected Targets

TypeDescriptionConfidence
SectorDefense
Verified
SectorDissident
Verified
SectorAerospace
Verified
RegionUnited States
Verified

Extracted IOCs

  • aeroconf2014[.]org
  • gmail[.]com
  • parmanpower[.]com
  • usa.gov[.]us
download

Tip: 4 related IOCs (0 IP, 4 domain, 0 URL, 0 email, 0 file hash) to this threat have been found.

Overlaps

Ajax Security TeamIranian Ajax Security Team Conducts Espionage on U.S. Defense Contractors

Source: FireEye - May 2014

Detection (one case): aeroconf2014[.]org

Hint: Overlaps are extracted automatically by examining the IOCs associated with all indexed threats and actors.

FAQs

Frequently Asked Questions about FLYING KITTEN's Campaign Against US Defense and Dissidents

FLYING KITTEN — also known as Ajax Security Team — is an Iranian threat group that CrowdStrike tracked from January 2014. The group combined two attack methods: first stealing credentials through fake login pages, then delivering Stealer malware to the same victims disguised as a "Browser Patch." Targets included US defense contractors and political dissidents. The campaign was publicly disclosed simultaneously by CrowdStrike and FireEye (who called it Operation Saffron Rose) in May 2014.

FLYING KITTEN is the CrowdStrike name for the Ajax Security Team, an Iran-based hacking group. Attribution was confirmed by an operational security mistake: the group initially registered its malicious domains under the Gmail address keyvan.ajaxtm@gmail.com, which directly links back to the Ajax Security Team. The group later updated domain registrations to a cover email (info@usa.gov.us) in an attempt to obscure their identity, but historical WHOIS records preserved the original association.

FLYING KITTEN pursued two parallel goals: credential theft and malware-based espionage. Stolen credentials gave the attackers access to victims' corporate accounts and internal systems. The Stealer malware then collected and exfiltrated data from compromised machines to an FTP server controlled by the attackers. Together, these two methods gave FLYING KITTEN both account access and direct file exfiltration from targeted defense contractors and political dissidents.

The confirmed targets were US-based defense contractors and political dissidents. The group also registered infrastructure suggesting potential broader targeting through a fake recruiting website (parmanpower[.]com) posing as a company in Erbil, Iraq, which could have been used to target individuals across many sectors. An earlier domain (aeroconf2014[.]org) impersonated the IEEE Aerospace Conference, indicating the aerospace and defense verticals were a primary focus in early 2014.

US defense contractors working in aerospace and defense hold sensitive information about weapons programs, military technology, and defense contracts that is directly valuable to Iranian intelligence. Political dissidents are targeted because the Iranian government monitors and seeks to suppress opposition figures living abroad. Both groups represent high-priority intelligence collection targets for Iran's state security apparatus.

FLYING KITTEN combined two techniques in sequence. First, the group registered domains that closely mimicked the names of target organizations or industry events — for example, a fake IEEE Aerospace Conference website — and hosted convincing fake login pages on those domains. When victims entered their real credentials, the attacker captured them. Victims were then immediately redirected to a page prompting them to download a "Browser Patch" or security update — which was actually the Stealer malware. Once installed, Stealer collected data from the compromised machine and transmitted it to an attacker-controlled FTP server. The entire chain — from credential theft to malware delivery — happened in a single victim session.

What made this campaign notable was the combination of credential theft and immediate malware delivery in a single session — which FireEye's concurrent reporting had treated as two separate tactics. FLYING KITTEN chained them together, maximizing the damage from a single victim interaction. The group's operational security failure — using a traceable Gmail address for domain registration — also provides a clear lesson: even small mistakes in infrastructure setup can expose the identity of a threat actor to investigators.

Always verify the URL in your browser's address bar before entering login credentials — spoofed domains may differ from the legitimate site by only a character or two. Use a password manager, which will not autofill credentials on impersonation domains it doesn't recognize. Never download a "browser update," "security patch," or any software prompted by a web page after a login — legitimate updates come from the application itself. Defense and aerospace employees should receive specific awareness training on credential-harvesting sites that mimic industry events and employer portals. Use CrowdStrike's published YARA rules to scan for Stealer malware (Stealer.Properties.Resources.resources, Stealer.pdb) and the FLYING KITTEN installer (IntelRapidStart.exe) on endpoints. Block known IOC domains at the network perimeter.

About Affiliation
Flying Kitten
Flying Kitten is an Iranian threat cluster that evolved from the hacktivist collective Ajax Security Team into a targeted espionage operation. Active since at least 2010, the group transitioned from website defacements to campaigns against US defense contractors, aerospace companies, and Iranian dissidents. FireEye documented a 2014 operation in which Flying Kitten distributed trojanized anti-censorship tools to Iranian dissidents while simultaneously targeting US defense sector organizations. The cluster is notable for the clear path from Iranian hacker forum activity to state-directed cyber operations.
View Flying Kitten's Insights