Adversary Intelligence — 2026-05-14
Chinese APTs Expand Targets and Update Backdoors in Recent Campaigns
Multiple Chinese state-sponsored APT groups including FamousSparrow and Twill Typhoon expanded their targeting to include energy firms in Azerbaijan and South Korea while deploying updated backdoor variants. FamousSparrow conducted multi-wave attacks exploiting Microsoft Exchange vulnerabilities against an Azerbaijani oil firm. Seedworm APT also abused signed binaries for DLL sideloading.