logo

FamousSparrow targets Azerbaijani energy sector in multi-wave espionage campaign

ID: dc09a5ca-3f2b-521e-94b1-a3adb1a9ac7e

STIX ID: report--dc09a5ca-3f2b-521e-94b1-a3adb1a9ac7e

Feed Name: Security Affairs

Threat Score
87/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Pierluigi Paganini

...
...

FamousSparrow, a Chinese-linked APT, repeatedly exploited a vulnerable Microsoft Exchange server (ProxyNotShell) to breach an Azerbaijani oil and gas company across three intrusions between December 2025 and February 2026, deploying Deed RAT and attempting Terndoor via DLL sideloading and loaders, moving laterally with RDP/SMB and establishing persistent footholds; the report highlights technical sophistication, reused access vectors, C2 masquerading as security vendors, and the strategic significance of targeting South Caucasus energy infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.