Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation
A "multi-wave intrusion" that targeted an unidentified Azerbaijani oil and gas corporation between late December 2025 and late February 2026 has been connected to a threat actor with ties to China, indicating an extension of its targeting.
With moderate-to-high confidence, Bitdefender has linked the activity to a hacking organization called FamousSparrow (also known as UAT-9244), which has some tactical overlap with clusters monitored under the names Earth Estries and Salt Typhoon.
The attack opens the door for the deployment of two different backdoors in three different waves: TernDoor, which was recently found in attacks targeting South American telecom infrastructure since 2024, and Deed RAT (also known as Snappybee), a ShadowPad successor utilized by several China-nexus espionag...

