← Back to Pulse Feed
PULSE DETAIL
A sophisticated multi-wave intrusion campaign targeted an Azerbaijani oil and gas company from late December 2025 through late February 2026, attributed with moderate-to-high confidence to the Chinese APT group FamousSparrow. The operation exploited unpatched Microsoft Exchange servers via ProxyShell and ProxyNotShell vulnerabilities to establish initial access. Attackers deployed two distinct backdoor families - Deed RAT and Terndoor - across three separate waves, demonstrating operational persistence by repeatedly exploiting the same entry point despite remediation attempts. Technical analysis revealed an evolved DLL sideloading technique using a two-stage trigger mechanism that gates execution through legitimate application control flow, effectively evading automated sandbox analysis. The campaign extended FamousSparrow's known targeting to South Caucasus energy infrastructure, coinciding with Azerbaijan's increased strategic importance to European energy security following disruptions in Russian and Mi...
MITRE ATT&CK & Malware Families
Indicators of Compromise (11)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| CVE | CVE-2021-31207 | — | 2026-05-20 | |
| CVE | CVE-2021-34473 | — | 2026-05-20 | |
| CVE | CVE-2021-34523 | — | 2026-05-20 | |
| CVE | CVE-2022-41040 | — | 2026-05-20 | |
| CVE | CVE-2022-41082 | — | 2026-05-20 | |
| FileHash-MD5 | 0554f3b69d39d175dd110d765c11347a | — | 2026-05-20 | |
| FileHash-MD5 | 505b55c2b68e32acb5ad13588e1491a5 | — | 2026-05-20 | |
| FileHash-MD5 | 762f787534a891eca8aa9b41330b4108 | — | 2026-05-20 | |
| URL | http://sentinelonepro.com:443 | — | 2026-05-20 | |
| URL | https://sentinelonepro.com:443 | — | 2026-05-20 | |
| domain | sentinelonepro.com | — | 2026-05-20 |