Chinese APT Exploits Microsoft Exchange to Breach Energy Sector Network
ID: 3a082805-5f07-5d70-a52c-8aff38d11011
STIX ID: report--3a082805-5f07-5d70-a52c-8aff38d11011
Feed Name: GBHackers
A Chinese state‑aligned APT (FamousSparrow) exploited unpatched Microsoft Exchange servers (ProxyNotShell/ProxyShell) at an Azerbaijani energy company between December 2025 and February 2026, using ASPX web shells to stage payloads, deploying Deed RAT via DLL sideloading and attempting to install the Terndoor backdoor via a Mofu loader and kernel driver; attackers moved laterally with RDP and Impacket tools to maintain long‑term espionage, posing strategic risk to European energy visibility and requiring credential rotation, memory/network forensics, and Exchange patching or isolation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
