Three times through the same door: FamousSparrow's patient campaign against Azerbaijan's energy sector- 239
December 25, 2025
A China-linked espionage group returned to the exact same compromised Microsoft Exchange server three separate times over two months, each visit bringing a different piece of malware, each attempt persisting despite the victim's remediation efforts in between. The target was an Azerbaijani oil and gas company — and the persistence itself is the story, because FamousSparrow's campaign lands precisely as Azerbaijan has quietly become one of Europe's most strategically important energy suppliers, filling a gap left by Russia's departure from the continent's gas map.
Bitdefender researchers attribute the intrusion with moderate-to-high confidence to FamousSparrow, a group overlapping with the broader Earth Estries and Salt Typhoon activity clusters — and the campaign marks the first documented instance of that activity cluster targeting energy infrastructure specifically in the South Caucasus. The timing is not incidental. Following the expiration of Russia's Ukraine gas transit agreement at the end of 2024 and the disruption of Strait of Hormuz shipments in early 2026, Azerbaijan has rapidly solidified its position as a strategic gas supplier to thirteen countries, including Germany and Austria. A China-aligned actor turning its attention to Azerbaijani energy infrastructure at this specific moment fits a broader pattern this publication has tracked repeatedly: espionage operations that follow the energy supply chains adversaries consider strategically load-bearing, arriving precisely as those supply chains gain new importance — in this case, as Chinese economic leverage through Belt and Road infrastructure investment grows in a region where Russian influence is simultaneously contracting.

The intrusion's technical arc reveals more discipline than sophistication for its own sake. Attackers gained initial access on December 25, 2025 by exploiting ProxyNotShell, a Microsoft Exchange vulnerability chain publicly disclosed back in 2022 — meaning the server at the center of this entire campaign remained exploitable more than three years after a patch existed. The first wave deployed Deed RAT, a successor to the well-documented ShadowPad malware used across multiple Chinese espionage groups, using an unusually careful DLL sideloading technique: the malicious library split its logic across two separate exported functions, patching a Windows API in memory during an early startup stage but withholding actual payload execution until the host application reached a later stage in its natural startup flow. That structural choice specifically defeats security sandboxes that only observe partial code execution in isolation — a deliberate design decision to survive automated analysis rather than just human inspection. Once established, the attackers moved laterally using stolen domain administrator credentials over RDP and Impacket-style SMB tooling, building redundant footholds within minutes of opening each new session.

The victim organization's remediation attempts didn't hold. Roughly a month after the initial compromise, the attackers returned through the identical Exchange server and attempted to deploy Terndoor, a backdoor previously observed in attacks against South American telecommunications infrastructure — this attempt was actually blocked by the target's security tooling before completion, though forensic artifacts confirmed the attribution. Undeterred, the group came back a third time at the end of February 2026, again through the same Exchange server, deploying a modified version of the original Deed RAT payload with an updated command-and-control domain deliberately disguised as a well-known endpoint security vendor, and relocating its files to a new directory — a small but telling sign that the operators suspected their earlier artifacts had been found and wanted better cover this time. Bitdefender's own framing of the pattern is direct: attackers will exploit and re-exploit the same access path for as long as it remains viable, adjusting tooling as needed, until the underlying vulnerability is patched and compromised credentials are actually rotated. In this case, that window stayed open for more than three years after the fix existed — a gap between disclosure and remediation that, in a sector adversaries have identified as strategically valuable, is doing far more to enable sustained espionage than any single piece of malware.