Threat group.View on attack.mitre.org
Ajax Security Team is a group that has been active since at least 2010 and believed to be operating out of Iran. By 2014 Ajax Security Team transitioned from website defacement operations to malware-based cyber espionage campaigns targeting the US defense industrial base and Iranian users of anti-censorship technologies.
| Technique | Procedure example |
|---|---|
| T1056.001 Keylogging |
Ajax Security Team has used CWoolger and MPK, custom-developed malware, which recorded all keystrokes on an infected system. |
| T1105 Ingress Tool Transfer |
Ajax Security Team has used Wrapper/Gholee, custom-developed malware, which downloaded additional malware to the infected system. |
| T1204.002 Malicious File |
Ajax Security Team has lured victims into executing malicious files. |
| T1555.003 Credentials from Web Browsers |
Ajax Security Team has used FireMalv custom-developed malware, which collected passwords from the Firefox browser storage. |
| T1566.001 Spearphishing Attachment |
Ajax Security Team has used personalized spearphishing attachments. |
| T1566.003 Spearphishing via Service |
Ajax Security Team has used various social media channels to spearphish victims. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.