In the high-stakes battleground of global energy security, unpatched servers act as open doors for relentless cyber spies.
Recently, a China-linked threat actor known as FamousSparrow launched a highly persistent cyberattack against an unnamed Azerbaijani oil and gas company.
Operating in the shadows between late December 2025 and late February 2026, the hackers repeatedly exploited vulnerabilities in a Microsoft Exchange server to penetrate the target network.
The attackers exploited the widely known ProxyNotShell and ProxyShell flaws to gain initial access, showcasing the severe dangers of delayed software patching.
Exchange Flaw Breaches Energy
The intrusion unfolded in three distinct phases, proving the attackers’ determination to maintain their grip on the victim’s network.
During the first wave, FamousSparrow deployed a malicious backdoor known as Deed RAT. To avoid setting off security alarms, the hackers used an advanced “DLL sideloading” technique.
By hijacking a legitimate LogMeIn Hamachi application binary (LMIGuardianSvc.exe), they tricked the system into loading their malicious code.

This evolved method waits for the host application’s natural startup process before triggering, effectively bypassing automated security sandboxes that only examine parts of the code.
When defenders attempted to clean the network, the hackers walked right back through the same unpatched Exchange server a month later. In this second wave, they attempted to deploy a different malware family, Terndoor, using a shellcode loader named Mofu.
Although this attempt was largely blocked by security software, the attackers returned for a third time in late February 2026.

This final wave introduced a newly modified version of Deed RAT, communicating with a deliberately designed command-and-control server that appeared to be a legitimate security vendor.
Bitdefender researchers noted that this level of operational discipline shows the attackers will repeatedly exploit the same path until the core vulnerability is fully patched and compromised credentials are rotated.

Indicators of Compromise
To assist security teams in hunting for these threats, researchers have extracted critical technical data from the attack. Below is a structured table of the key Indicators of Compromise (IOCs) observed during this campaign.
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.