logo

Chinese APT FamousSparrow Weaponizes Evolved Deed RAT Against Azerbaijani Energy Infrastructure

ID: 71b90afc-b479-58cc-bc52-664cb2e7cd22

STIX ID: report--71b90afc-b479-58cc-bc52-664cb2e7cd22

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Ddos

...
...

Bitdefender Labs describes a multi-wave APT intrusion (Dec 2025–Feb 2026) against an Azerbaijani energy company attributed to FamousSparrow, using ProxyNotShell to drop web shells and deploy a stealthy Deed RAT via LogMeIn Hamachi DLL side‑loading, with a later attempted Terndoor kernel-driver deployment; the malware uses a two-stage in-memory hook to evade sandboxes and the final variant masqueraded C2 traffic over HTTPS to sentinelonepro.com:443, and the report recommends real-time memory scanning and monitoring suspicious service/driver creation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.