Flying Kitten is an early Iranian threat group, documented by FireEye in 2014 as the Ajax Security Team behind Operation Saffron Rose, that transitioned from web defacement into targeted cyber-espionage against the U.S. defense industrial base and Iranian dissidents using phishing and custom Stealer/Sayad malware.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Flying Kitten was detailed by FireEye/Mandiant in the May 2014 'Operation Saffron Rose' report, which documented the Ajax Security Team's evolution from a patriotic Iranian hacktivist collective (known for web defacements circa 2010) into an espionage-focused actor. CrowdStrike tracks the cluster as Flying Kitten. Attribution to Iran is medium confidence, resting on Persian-language artifacts, operator personas, and targeting aligned with Iranian interests; the group has no formal MITRE Group ID, a limitation flagged here.
The group's tradecraft relied on social engineering and credential theft rather than advanced exploitation: fake login/anti-censorship pages, spearphishing, and malicious installers masquerading as VPN or security software to deliver the Stealer keylogger/infostealer and the Sayad (Stealer) toolkit. This low-cost, high-touch phishing model was effective against under-defended individual targets and dissidents.
MENA relevance runs two ways. Domestically and regionally, Flying Kitten targeted Iranian dissidents, anti-censorship users, and human-rights activists inside Iran and across the diaspora — using fabricated tools purporting to bypass Iranian internet controls. Simultaneously it pursued the U.S. defense industrial base, reflecting an early blend of internal-repression and foreign-espionage missions characteristic of Iran's maturing cyber program.
Flying Kitten / Ajax Security Team faded under this name after 2014 following public exposure; its operators and tradecraft are assessed to have contributed to successor IRGC-aligned clusters (with overlaps noted toward Rocket Kitten and the broader Kitten ecosystem). It is included as a formative early-Iran historical entry, flagged medium confidence and G-ID-less.