{"id":245156,"date":"2026-05-13T09:00:00","date_gmt":"2026-05-13T13:00:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/05\/13\/azerbaijani-energy-firm-hit-by-repeated-microsoft-exchange-exploitation\/"},"modified":"2026-05-13T10:50:06","modified_gmt":"2026-05-13T14:50:06","slug":"azerbaijani-energy-firm-hit-by-repeated-microsoft-exchange-exploitation","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/05\/13\/azerbaijani-energy-firm-hit-by-repeated-microsoft-exchange-exploitation\/","title":{"rendered":"Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/azerbaijani-energy-firm-hit-by-repeated.html\">Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/azerbaijani-energy-firm-hit-by-repeated.html\">https:\/\/thehackernews.com\/2026\/05\/azerbaijani-energy-firm-hit-by-repeated.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-05-13 09:00:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">May 13, 2026<\/span><\/span><span class=\"p-tags\">Cyber Espionage \/ Malware<\/span><\/p>\n<p>A threat actor with affiliations to China has been linked to a &#8220;multi-wave intrusion&#8221; targeting an unnamed Azerbaijani oil and gas company between late December 2025 and late February 2026, marking an expansion of its targeting.<\/p>\n<p>The activity has been attributed by Bitdefender with moderate-to-high confidence to a hacking group known as <strong>FamousSparrow<\/strong> (aka UAT-9244), which shares some level of tactical overlap with clusters tracked under the monikers Earth Estries and Salt Typhoon.<\/p>\n<p>The attack paves the way for the deployment of two distinct backdoors across three separate waves: Deed RAT (aka Snappybee), a successor of ShadowPad that&#8217;s used by multiple China-nexus espionage groups, and TernDoor, which was recently discovered in attacks targeting telecommunications infrastructure in South America since 2024.<\/p>\n<p>What&#8217;s notable about the campaign is that it repeatedly leveraged the same vulnerable Microsoft Exchange Server entry point despite several remediation attempts, swapping backdoors each time: Deed RAT on December 25, 2025, TernDoor in late January\/early February 2026, and a modified Deed RAT in late February 2026. The attackers are assessed to have exploited the ProxyNotShell chain to obtain initial access.<\/p>\n<p>&#8220;This targeting extends the known FamousSparrow victimology into a region where Azerbaijan&#8217;s role in European energy security has materially increased following the 2024 expiration of Russia&#8217;s Ukraine gas transit agreement and 2026 Strait of Hormuz disruptions,&#8221; the Romanian cybersecurity company said in a report shared with The Hacker News.<\/p>\n<p>&#8220;The intrusion illustrates that actors will exploit and re-exploit the same access path until the original vulnerability is patched, compromised credentials are rotated, and the attacker&#8217;s ability to return is fully disrupted.&#8221;<\/p>\n<p><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"1032\" data-original-width=\"2048\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjsIgFauFZQDetOnnbq3AGDn6TCRga0rwvsUFAwFZ08hIr1jpqD4CmZSiibEWcHxrxqNSegqV7RtRs8fuAdPsprbAkY5xVKe73nhwSBcquMNH8eQV1OI5yEk3ssc0OkaRKXPq94pEuZ5iKaX4Ap3XW789igPTE506TCgBETCWdWQB4KXTTqtDUz8flE6YU2\/s1600\/dll.png\"\/><\/p>\n<p>The initial access is said to have been followed by attempts to deploy web shells to establish a persistent foothold, and ultimately&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/05\/azerbaijani-energy-firm-hit-by-repeated.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation https:\/\/thehackernews.com\/2026\/05\/azerbaijani-energy-firm-hit-by-repeated.html Publish Date: 2026-05-13 09:00:00 Source&#8230;<\/p>\n","protected":false},"author":1,"featured_media":245157,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjOfGXVOYqF2EcrcnYIDCnTYdmWpV-uaZ5nV0_0ukZ8uCk19wFFOax_VvgwO8LtlIkVo8pvcSSBs8Afc66yo2PbiMDjq4UDqnytAqP-Nq8CqTOfEtqwuWRmjbUpRYzqaAXFnRiXozR34fXAPE8O6Gcix6f08Sped3oVUXcjIOTE04N8IInA0qVeG0Sc6LzB\/s1600\/energy-cyberattack.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,31,35,32,34,27],"class_list":["post-245156","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-exploit","tag-hacker","tag-malware","tag-threat-actor","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/245156"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=245156"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/245156\/revisions"}],"predecessor-version":[{"id":245158,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/245156\/revisions\/245158"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/245157"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=245156"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=245156"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=245156"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}