China-linked group spied on an Azerbaijani oil and gas company
The China-linked threat actor FamousSparrow has been linked to a sustained cyber espionage campaign against an Azerbaijani oil and gas company between December 2025 and February 2026. Researchers at Bitdefender believe the attacks were likely motivated by Azerbaijan's growing importance as an energy supplier to Europe.
The attackers reportedly gained initial access by exploiting Microsoft Exchange vulnerabilities, including the ProxyNotShell chain, before deploying web shells and custom malware such as Deed RAT and the Terndoor backdoor. The operation involved DLL sideloading, lateral movement using RDP and Impacket tooling, and repeated attempts to regain access after remediation. Bitdefender notes an evolution in tradecraft, including a more sophisticated sideloading method that modifies exported functions rather than replacing the DLL outright. Malware components were disguised as legitimate LogMeIn Hamachi software. The activity is assessed with moderate-to-high confidence as FamousSparrow, also associated with the broader Salt Typhoon and Earth Estries ecosystem.
What this means for your organisation
The campaign shows that energy supply to Europe is an intelligence target in its own right, and the Norwegian energy sector is no exception. Two details deserve attention: the attackers entered through long-known Exchange vulnerabilities, and they returned repeatedly after the organisation believed it had cleaned up. Incomplete remediation is as much a risk as the intrusion itself, and for organisations under NIS2 this is a board-level question about how thoroughly an incident is actually closed.
Berigo recommends
- Verify that Exchange installations are fully patched, and search for web shells in directories the service exposes.
- Require that post-incident remediation covers every access path and persistence mechanism, not just the first machine discovered.
- Monitor for DLL sideloading and for software impersonating legitimate remote administration tools.
- Raise intelligence-driven threats against the energy sector in the board's annual risk review.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch