FamousSparrow targets Azerbaijani energy sector in multi-wave espionage campaign
ID: dc09a5ca-3f2b-521e-94b1-a3adb1a9ac7e
STIX ID: report--dc09a5ca-3f2b-521e-94b1-a3adb1a9ac7e
Feed Name: Security Affairs
FamousSparrow, a Chinese-linked APT, repeatedly exploited a vulnerable Microsoft Exchange server (ProxyNotShell) to breach an Azerbaijani oil and gas company across three intrusions between December 2025 and February 2026, deploying Deed RAT and attempting Terndoor via DLL sideloading and loaders, moving laterally with RDP/SMB and establishing persistent footholds; the report highlights technical sophistication, reused access vectors, C2 masquerading as security vendors, and the strategic significance of targeting South Caucasus energy infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
