Adversary Intelligence — 2026-05-13

China FamousSparrow APT Targets South Caucasus Energy Firm

Bitdefender on May 13 attributed a three-wave intrusion against an unnamed Azerbaijani oil and gas company, active from late December 2025 through late February 2026, to FamousSparrow with moderate-to-high confidence. The attackers entered via the ProxyNotShell exploit chain on the victim's Microsoft Exchange server and deployed Deed RAT through a two-stage DLL sideloading technique that gates payload execution behind the LogMeIn Hamachi binary's normal startup sequence, preventing the malicious logic from triggering under partial or sandbox analysis. The group returned to the same unpatched Exchange entry point across all three waves, cycling through Deed RAT, TernDoor, and a modified Deed RAT while also conducting lateral movement within the network. Bitdefender, noting substantial overlap between FamousSparrow and the Earth Estries toolset, states this is the first public documentation of the cluster targeting energy infrastructure in the South Caucasus.

Analysis
Re-exploitation of the same Exchange server across three waves, each with an evolved payload, reflects collection requirements sustained enough to justify repeated operational exposure. Azerbaijan's expanded gas supply role since the Russia-Ukraine transit lapse at end-2024 gives the targeting strategic coherence, though access to European energy supply-chain nodes may have been the criterion with the country incidental. The two-stage DLL sideloading technique gates execution behind LogMeIn Hamachi's full startup sequence to defeat sandbox analysis by design, per Bitdefender alone, without independent corroboration. First documentation against South Caucasus energy infrastructure, combined with the digital quartermaster model distributing techniques across Chinese APT clusters, makes this loader a likely near-term indicator across the Earth Estries ecosystem.
3 sources
  1. China's FamousSparrow APT Nests in South Caucasus Energy Firm - Dark Reading
  2. FamousSparrow APT Targets Azerbaijani Oil and Gas Industry - Bitdefender
  3. Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation - The Hacker News

View in full brief →

UNCLASSIFIED // OPEN SOURCE