logo

Chinese APT Hackers Exploit Microsoft Exchange to Breach Energy Sector Network

ID: 9251f7b2-5029-5dfa-bc8b-de4824ee05b2

STIX ID: report--9251f7b2-5029-5dfa-bc8b-de4824ee05b2

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-05-22

Author: Tushar Subhra Dutta

...
...

FamousSparrow, a Chinese state-linked APT, executed a sustained multi-wave espionage campaign from December 2025 to February 2026 against an Azerbaijani oil and gas company by exploiting unpatched Microsoft Exchange (ProxyNotShell CVE-2022-41040/CVE-2022-41082). The attackers deployed Deed RAT and Terndoor backdoors using sophisticated DLL sideloading and web shells, attempted kernel-level persistence, reused compromised servers across waves, and used evasive techniques (split export functions, impersonated C2 domains); the report documents IoCs and recommends immediate Exchange patching, credential rotation, and targeted monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.