Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Hackers Breach Oil Sector via Microsoft Exchange

Chinese Hackers Breach Oil Sector via Microsoft Exchange

Posted on May 14, 2026 By CWS

A hacking group associated with the Chinese state, known as FamousSparrow, has breached an Azerbaijani oil and gas company. The group exploited vulnerabilities in an unpatched Microsoft Exchange server, allowing them to install multiple backdoors within the network.

Detailed Attack Timeline

The breach spanned from December 2025 to February 2026, marking a significant intrusion into the energy infrastructure in the South Caucasus. During this time, the attackers returned to the compromised server on three occasions, each time introducing different malware families and adapting their strategies to counteract defensive measures.

This persistent effort indicates a well-planned espionage campaign rather than a mere opportunistic attack. Bitdefender researchers, who monitored the attack, attributed it to FamousSparrow, citing overlaps with the Earth Estries threat cluster.

Strategic Importance of the Breach

The timing of this attack coincides with Azerbaijan’s increased importance as a gas supplier to Europe, following disruptions from the expiration of Russia’s Ukraine transit deal and issues in the Strait of Hormuz. This has raised concerns about the security of critical energy infrastructures.

The operation involved two backdoor families, Deed RAT and Terndoor, and showcased an evolved DLL sideloading technique designed to evade automated security defenses. This sophisticated approach highlights the threat group’s advanced capabilities in targeting energy sectors.

Technical Aspects of the Intrusion

The initial breach was detected on December 25, 2025, when a web shell was written into a server directory using the ProxyNotShell exploit chain. This exploit leverages vulnerabilities CVE-2022-41040 and CVE-2022-41082, enabling remote code execution on unpatched servers.

Subsequent attacks saw the deployment of additional web shells and a three-component malware chain masquerading as the LogMeIn Hamachi VPN application. This included a loader file and a Deed RAT payload, which was decrypted using AES-128 and RC4.

Advanced Evasion Techniques

The attackers employed a novel DLL sideloading technique, splitting malicious code across two export functions, which delayed execution until specific conditions were met. This method evades detection by security tools that only analyze parts of the code.

In later waves, the attackers attempted to install a kernel driver through the Terndoor backdoor but were thwarted. They also used a modified Deed RAT to camouflage their activities under a reputable security vendor’s domain.

Recommendations for Security Teams

Organizations should promptly apply Microsoft Exchange patches and change exposed credentials. Monitoring should focus on IIS worker processes, unsigned binaries, and suspicious network activity, especially involving administrative accounts and PowerShell.

Indicators of compromise include specific filenames and hash values associated with the malicious activities. Maintaining vigilance over these indicators can help detect and mitigate similar threats in the future.

Cyber Security News Tags:advanced malware, APT, Azerbaijan, Chinese hackers, cyber espionage, Cybersecurity, Deed RAT, DLL Sideloading, energy sector, FamousSparrow, Microsoft Exchange, network breach, persistent access, ProxyNotShell, TernDoor

Post navigation

Previous Post: Sandworm Hackers Shift Focus to Critical Infrastructure
Next Post: Mythos AI Uncovers macOS Flaws in Apple Security

Related Posts

New PyStoreRAT Malware Targets IT and OSINT Experts New PyStoreRAT Malware Targets IT and OSINT Experts Cyber Security News
Lovable AI Platform Vulnerability Exposes Project Data Lovable AI Platform Vulnerability Exposes Project Data Cyber Security News
0APT Ransomware: Illusion of Data Breaches Exposed 0APT Ransomware: Illusion of Data Breaches Exposed Cyber Security News
Silver Fox Hackers Using Weaponized Google Translate Tools to Deploy Windows Malware Silver Fox Hackers Using Weaponized Google Translate Tools to Deploy Windows Malware Cyber Security News
New EDR-Redir V2 Blinds Windows Defender on Windows 11 With Fake Program Files New EDR-Redir V2 Blinds Windows Defender on Windows 11 With Fake Program Files Cyber Security News
New Android Bug Impacts Volume Buttons Functionality with “Select to Speak” Enabled New Android Bug Impacts Volume Buttons Functionality with “Select to Speak” Enabled Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Claude Code to Steal OAuth Tokens
  • New Tool EDRChoker Disrupts EDR Agents via QoS Throttling
  • Emphere Secures $2.1M to Enhance AI Security Solutions
  • Instagram Addresses Password Reset Vulnerability
  • CISA Alerts on Linux Kernel Vulnerability Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Claude Code to Steal OAuth Tokens
  • New Tool EDRChoker Disrupts EDR Agents via QoS Throttling
  • Emphere Secures $2.1M to Enhance AI Security Solutions
  • Instagram Addresses Password Reset Vulnerability
  • CISA Alerts on Linux Kernel Vulnerability Threat

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark