Hackers from China have been linked to a “multi-wave intrusion” targeting an unnamed oil and gas company in Azerbaijan via Microsoft Exchange, between late December 2025 and late February 2026, marking an expansion of its targeting. The activity has been attributed by Bitdefender with medium to high confidence to a hacking group known as FamousSparrow (also known as UAT-9244), which shares some level of tactical overlap with groups monitored under the aliases Earth Estries and Salt Typhoon.
See also: Microsoft fixes critical vulnerability in Entra ID Agent Administrator

The attack paves the way for the deployment of two distinct backdoors in three separate waves: the Deed RAT (also known as Snappybee), a successor to ShadowPad used by multiple espionage groups with connections to China, and TernDoor, which was recently discovered in attacks targeting telecommunications infrastructure in South America since 2024. What is notable about the campaign is that it repeatedly exploited the same Microsoft Exchange Server vulnerable entry point despite several remediation attempts, changing backdoors each time: the Deed RAT on December 25, 2025, TernDoor in late January/early February 2026, and a modified Deed RAT in late February 2026.
The attackers are believed to have exploited the ProxyNotShell chain to gain initial access. “ This targeting extends FamousSparrow’s known victimology to a region where Azerbaijan’s role in Europe’s energy security has substantially increased following the expiration of Russia’s gas transit agreement via Ukraine in 2024 and disruptions in the Strait of Hormuz in 2026 ,” Romanian cybersecurity firm Bitdefender said in a report .
See also: Microsoft 365 Backup: Restore individual files and folders

“The intrusion indicates that the perpetrators will exploit and re-exploit the same access path until the initial vulnerability is patched, the compromised credentials are refreshed, and the attacker’s ability to return is completely cut off.” The initial access is said to have been followed by attempts to deploy web shells to establish a persistent base and ultimately the deployment of the Deed RAT using a sophisticated DLL side-loading technique that leverages the legitimate LogMeIn Hamachi binary to load and launch a malicious DLL responsible for executing the main payload.
Attacks have also been found to conduct lateral movement to expand their reach within the compromised network and establish a backup base to ensure resilience in case the activity is detected and removed.
The second wave occurred nearly a month after the initial intrusion, with the adversary attempting unsuccessfully to use DLL side-loading to drop TernDoor via Mofu Loader, a shellcode loader previously attributed to GroundPeony. The Azerbaijani company was targeted for a third time towards the end of February 2026, when the threat actors again attempted to deploy a modified version of the Deed RAT, indicating active efforts to improve and evolve their malware arsenal.
See also: Microsoft Patch Tuesday February 2026: Fixes for 58 vulnerabilities

This object uses “sentinelonepro [.]com” for command and control (C2). “This intrusion should not be viewed as an isolated breach, but rather as a continuous and adaptive operation conducted by an actor who repeatedly sought to regain and expand access to the victim’s environment,” Bitdefender said. “In multiple waves of activity, the same access path was revisited, new payloads were introduced, and additional bases were established, highlighting a high degree of persistence and operational discipline.”
