Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators APT Targets Azerbaijani Oil and Gas Industry

https://sentinelonepro.com:443

TLP:CLEAR
Active

URL

Description

A sophisticated multi-wave intrusion campaign targeted an Azerbaijani oil and gas company from late December 2025 through late February 2026, attributed with moderate-to-high confidence to the Chinese APT group FamousSparrow. The operation exploited unpatched Microsoft Exchange servers via ProxyShell and ProxyNotShell vulnerabilities to establish initial access. Attackers deployed two distinct backdoor families - Deed RAT and Terndoor - across three separate waves, demonstrating operational persistence by repeatedly exploiting the same entry point despite remediation attempts. Technical analysis revealed an evolved DLL sideloading technique using a two-stage trigger mechanism that gates execution through legitimate application control flow, effectively evading automated sandbox analysis. The campaign extended FamousSparrow's known targeting to South Caucasus energy infrastructure, coinciding with Azerbaijan's increased strategic importance to European energy security following disrupti...

Sightings (0)

No sightings recorded yet

Details

Name / Label
APT Targets Azerbaijani Oil and Gas Industry
Pattern Type
STIX
Confidence
75%
Valid From
May 26, 2026 02:45
Total Sightings
0
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of https://sentinelonepro.com:443

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.