Flying_Kitten__2014__fireeye-operation-saffron-rose.pdf
ID: 770ad020-376c-4bdd-ac5b-da2d9662284f
STIX ID: report--770ad020-376c-4bdd-ac5b-da2d9662284f
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2014-08-13
Last Modified Date: 2014-08-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye's "Operation Saffron Rose" documents the Ajax Security Team—an Iranian-affiliated hacking group—that moved from defacements to targeted cyber-espionage in 2013–2014. The report analyzes a custom .NET backdoor family called "Stealer" (dropper IntelRS.exe, AppTransferWiz.dll FTP exfiltration), its builder and Base64 tooling, attack vectors (spearphishing with fake conference site, credential phishing, trojanized anti-censorship tools), C2 domains/IPs, sample hashes/timestamps, and victimology (including 77 victims, many in Iran and targeting U.S. defense contractors), and provides contextual attribution and TTPs.
