
"A threat actor with affiliations to China has been linked to a "multi-wave intrusion" targeting an unnamed Azerbaijani oil and gas company between late December 2025 and late February 2026, marking an expansion of its targeting."
"What's notable about the campaign is that it repeatedly leveraged the same vulnerable Microsoft Exchange Server entry point despite several remediation attempts, swapping backdoors each time: Deed RAT on December 25, 2025, TernDoor in late January/early February 2026, and a modified Deed RAT in late February 2026."
"The attackers are assessed to have exploited the ProxyNotShell chain to obtain initial access. "This targeting extends the known FamousSparrow victimology into a region where Azerbaijan's role in European energy security has materially increased following the 2024 expiration of Russia's Ukraine gas transit agreement and 2026 Strait of Hormuz disruptions," the Romanian cybersecurity company said in a report shared with The Hacker News."
""The intrusion illustrates that actors will exploit and re-exploit the same access path until the original vulnerability is patched, compromised credentials are rotated, and the attacker's ability to return is fully disrupted." The initial access is said to have been followed by attempts to deploy web shells to establish a persistent foothold, and ultimately deploy Deed RAT using an evolved DL"
A China-affiliated threat actor linked to FamousSparrow conducted a multi-wave intrusion against an unnamed Azerbaijani oil and gas company from late December 2025 to late February 2026. The campaign used the same Microsoft Exchange Server entry point despite remediation attempts, deploying Deed RAT on December 25, 2025, TernDoor in late January or early February 2026, and a modified Deed RAT in late February 2026. Initial access was obtained through the ProxyNotShell exploitation chain. After gaining access, attackers attempted to deploy web shells for persistence and then deployed Deed RAT using an evolved DL mechanism. The targeting expands known FamousSparrow victimology into a region tied to European energy security.
Read at The Hacker News
Unable to calculate read time
Collection
[
|
...
]