logo

Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation

ID: 157aba6b-a2d8-5f8c-9601-9377f74de282

STIX ID: report--157aba6b-a2d8-5f8c-9601-9377f74de282

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-05-13

Date Updated: 2026-05-14

Author: [email protected] (The Hacker News)

...
...

Bitdefender attributes a multi-wave cyber‑espionage campaign against an Azerbaijani oil and gas company (Dec 2025–Feb 2026) to FamousSparrow (UAT-9244), which exploited a Microsoft Exchange ProxyNotShell chain to repeatedly regain access, deploy web shells and two backdoors (Deed RAT/Snappybee and TernDoor) via evolved DLL side‑loading and loaders like Mofu, performed lateral movement to establish resilient footholds, and used C2 infrastructure (e.g., sentinelonepro.com); the activity demonstrates sustained, adaptive targeting of critical energy infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.