logo

Chinese APT Exploits Microsoft Exchange to Breach Energy Sector Network

ID: 3a082805-5f07-5d70-a52c-8aff38d11011

STIX ID: report--3a082805-5f07-5d70-a52c-8aff38d11011

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Mayura Kathir

...
...

A Chinese state‑aligned APT (FamousSparrow) exploited unpatched Microsoft Exchange servers (ProxyNotShell/ProxyShell) at an Azerbaijani energy company between December 2025 and February 2026, using ASPX web shells to stage payloads, deploying Deed RAT via DLL sideloading and attempting to install the Terndoor backdoor via a Mofu loader and kernel driver; attackers moved laterally with RDP and Impacket tools to maintain long‑term espionage, posing strategic risk to European energy visibility and requiring credential rotation, memory/network forensics, and Exchange patching or isolation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.