216.73.217.22

APT Targets Azerbaijani Oil and Gas Industry

· Published 20/05/2026 11:10 · Modified 21/05/2026 16:11

Export JSON

Essential information

Published
20/05/2026 11:10
Modified
21/05/2026 16:11
Tags
2026-05-20 azerbaijan chinese apt deed rat dll sideloading earth estries energy sector exchange exploitation famoussparrow terndoor
Related entities
5 vulnerabilities (cve), 2 observables, 1 intrusion sets (apt), 20 techniques (mitre), 3 malware, 3 others

Description

A sophisticated multi-wave intrusion campaign targeted an Azerbaijani oil and gas company from late December 2025 through late February 2026, attributed with moderate-to-high confidence to the group . The operation exploited unpatched Microsoft Exchange servers via ProxyShell and ProxyNotShell vulnerabilities to establish initial access. Attackers deployed two distinct backdoor families - and - across three separate waves, demonstrating operational persistence by repeatedly exploiting the same entry point despite remediation attempts. Technical analysis revealed an evolved technique using a two-stage trigger mechanism that gates execution through legitimate application control flow, effectively evading automated sandbox analysis. The campaign extended 's known targeting to South Caucasus energy infrastructure, coinciding with 's increased strategic importance to European energy security following disruptions in Russian and Mi...

External references