A threat actor affiliated with China conducted a sustained, three-phase intrusion against an Azerbaijani oil and gas company between late December 2025 and late February 2026.

A China-affiliated hacking group repeatedly breached an Azerbaijani oil and gas company over a two-month period, reusing the same Microsoft Exchange Server vulnerability to deploy evolving malware and maintain persistent access to the victim’s network.
Bitdefender, a Romania-based cybersecurity company, attributed the activity with moderate-to-high confidence to the hacking group FamousSparrow, also tracked as UAT-9244. The group shares tactical similarities with threat clusters known as Earth Estries and Salt Typhoon.
The campaign unfolded across three separate waves between late December 2025 and late February 2026 and involved the deployment of two backdoors: Deed RAT, also known as Snappybee, and TernDoor. Researchers identified the operation as a sustained espionage effort marked by repeated attempts to re-establish access even after remediation measures were implemented.
The attackers are believed to have gained initial access by exploiting the ProxyNotShell vulnerability chain in Microsoft Exchange Server. The first intrusion occurred on Dec. 25, 2025, when the group deployed Deed RAT. A second wave followed in late January and early February 2026 with attempts to introduce the TernDoor backdoor. A third intrusion in late February involved a modified version of Deed RAT.
Researchers said the campaign reflects a growing focus on Azerbaijan’s strategic energy sector as the country’s importance to European energy security has increased following the expiration of Russia’s Ukraine gas transit agreement in 2024 and disruptions in the Strait of Hormuz in 2026.
The intrusions also demonstrated the attackers’ persistence. The same Exchange Server entry point was repeatedly exploited after remediation attempts, indicating the underlying vulnerability remained unpatched or that compromised credentials were not fully rotated.
The attackers attempted to establish long-term persistence through web shells and later used an evolved DLL side-loading technique to deploy Deed RAT. The method abused the legitimate LogMeIn Hamachi application to load a malicious DLL that executed the malware payload.
Researchers said the malware modified two exported functions within the rogue DLL, creating a staged execution process tied to the legitimate application’s normal control flow. The technique was designed to improve defense evasion beyond conventional DLL side-loading attacks.
The campaign also involved lateral movement within the victim’s network to broaden access and create redundant footholds that could survive partial remediation efforts.
During the second wave of activity, the attackers unsuccessfully attempted to deploy TernDoor using Mofu Loader, a shellcode loader previously associated with the China-linked group GroundPeony.
The third wave featured another modified version of Deed RAT that communicated with the command-and-control domain “sentinelonepro[.]com,” indicating ongoing efforts to refine the malware toolkit and maintain operational access.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543