Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagecritical-infrastructure-threatinternet-facing-service-vulnerabilityremote-access-implant

FamousSparrow Repeatedly Breached Azerbaijani Oil Firm via Microsoft Exchange

Updated 1mo agoFirst seen May 13, 20264 sources

A China-linked threat actor tracked as FamousSparrow and UAT-9244 repeatedly compromised an unnamed Azerbaijani oil and gas company in a multi-wave campaign that ran from late December 2025 through late February 2026. Bitdefender assessed with moderate-to-high confidence that the attackers gained initial access by exploiting a vulnerable Microsoft Exchange Server, likely through the ProxyNotShell chain, and repeatedly re-entered the environment even after remediation efforts. The targeting expands the group's known victimology into Azerbaijan, a country with growing strategic importance to European energy security.

Across three intrusion waves, the operators deployed or attempted to deploy Deed RAT (also known as Snappybee), TernDoor, and a modified version of Deed RAT, while using web shells, lateral movement, and redundant footholds to preserve access. Researchers also reported an evolved DLL side-loading technique that abused the legitimate LogMeIn Hamachi binary to help evade defenses. The operation was described as sustained and adaptive, with the attackers changing payloads and persistence methods while continuing to exploit the same Exchange entry point.

Share:
FamousSparrow Repeatedly Breached Azerbaijani Oil Firm via Microsoft Exchange
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
May 13, 20261mo ago

Bitdefender links campaign to FamousSparrow and expands victimology

By May 2026, Bitdefender publicly attributed the multi-wave intrusion to FamousSparrow with moderate-to-high confidence, noting that the campaign expanded the group's known targeting into Azerbaijan's strategically important energy sector.

Feb 28, 20264mo ago

Intrusion progresses through three payload waves

Across three distinct waves ending in late February 2026, the operators deployed or attempted to deploy Deed RAT, then TernDoor, and later a modified Deed RAT, while using web shells, lateral movement, redundant footholds, and an evolved DLL side-loading technique involving LogMeIn Hamachi.

Jan 1, 20266mo ago

Attackers return in multiple waves despite remediation attempts

Between late December 2025 and late February 2026, the attackers repeatedly re-entered the victim environment through the same Exchange entry point even after remediation efforts, showing sustained and adaptive access operations.

Dec 25, 20256mo ago

FamousSparrow begins intrusion into Azerbaijani oil and gas company

In late December 2025, a China-linked threat actor tracked as FamousSparrow/UAT-9244 gained initial access to an unnamed Azerbaijani oil and gas company by exploiting a vulnerable Microsoft Exchange Server, likely via the ProxyNotShell chain.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

16 LINKEDOpen in app
Threat actors
2 linked
Organizations
8 linked
Microsoft CorporationLogmeinBitdefenderSentinelOneipinfo.ioAzerbaijani oil and gas companyGoogleThe Hacker News
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

FamousSparrow Repeatedly Breached Azerbaijani Oil Firm via Microsoft Exchange | Mallory