PULSE NAME
APT Targets Azerbaijani Oil and Gas Industry
WHITE GhostEmperor AlienVault 2026-05-20 Modified: 2026-05-21
11
IOCs
MEDIUM VOLUME
A sophisticated multi-wave intrusion campaign targeted an Azerbaijani oil and gas company from late December 2025 through late February 2026, attributed with moderate-to-high confidence to the Chinese APT group FamousSparrow. The operation exploited unpatched Microsoft Exchange servers via ProxyShell and ProxyNotShell vulnerabilities to establish initial access. Attackers deployed two distinct backdoor families - Deed RAT and Terndoor - across three separate waves, demonstrating operational persistence by repeatedly exploiting the same entry point despite remediation attempts. Technical analysis revealed an evolved DLL sideloading technique using a two-stage trigger mechanism that gates execution through legitimate application control flow, effectively evading automated sandbox analysis. The campaign extended FamousSparrow's known targeting to South Caucasus energy infrastructure, coinciding with Azerbaijan's increased strategic importance to European energy security following disruptions in Russian and Mi...
Indicators of Compromise (11)
All CVE FileHash-MD5 URL domain
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2021-31207 2026-05-20
CVE CVE-2021-34473 2026-05-20
CVE CVE-2021-34523 2026-05-20
CVE CVE-2022-41040 2026-05-20
CVE CVE-2022-41082 2026-05-20
FileHash-MD5 0554f3b69d39d175dd110d765c11347a 2026-05-20
FileHash-MD5 505b55c2b68e32acb5ad13588e1491a5 2026-05-20
FileHash-MD5 762f787534a891eca8aa9b41330b4108 2026-05-20
URL http://sentinelonepro.com:443 2026-05-20
URL https://sentinelonepro.com:443 2026-05-20
domain sentinelonepro.com 2026-05-20