ATT&CKGroupsAjax Security Team

Ajax Security Team

G0130

Threat group.View on attack.mitre.org

About this group

Ajax Security Team is a group that has been active since at least 2010 and believed to be operating out of Iran. By 2014 Ajax Security Team transitioned from website defacement operations to malware-based cyber espionage campaigns targeting the US defense industrial base and Iranian users of anti-censorship technologies.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1056.001
Keylogging

Ajax Security Team has used CWoolger and MPK, custom-developed malware, which recorded all keystrokes on an infected system.

T1105
Ingress Tool Transfer

Ajax Security Team has used Wrapper/Gholee, custom-developed malware, which downloaded additional malware to the infected system.

T1204.002
Malicious File

Ajax Security Team has lured victims into executing malicious files.

T1555.003
Credentials from Web Browsers

Ajax Security Team has used FireMalv custom-developed malware, which collected passwords from the Firefox browser storage.

T1566.001
Spearphishing Attachment

Ajax Security Team has used personalized spearphishing attachments.

T1566.003
Spearphishing via Service

Ajax Security Team has used various social media channels to spearphish victims.

Software2

Campaigns0

None recorded.

References1

  1. FireEye Operation Saffron Rose 2013 Open source
    Villeneuve, N. et al.. (2013). OPERATION SAFFRON ROSE . Retrieved May 28, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.