# Chinese-Linked Hackers Exploit Same Microsoft Exchange Vulnerability Repeatedly Against Azerbaijani Energy Firm, Deploying Multiple Backdoors


A three-month intrusion campaign demonstrates the persistence and adaptability of state-sponsored threat actors targeting critical energy infrastructure in a geopolitically sensitive region.


A China-affiliated hacking group launched a sustained, multi-wave cyber espionage campaign against an Azerbaijani oil and gas company between late December 2025 and late February 2026, exploiting the same Microsoft Exchange vulnerability across three separate intrusion attempts despite interim remediation efforts. The campaign, attributed to FamousSparrow (also tracked as UAT-9244), resulted in the deployment of two distinct backdoors and demonstrates a sophisticated, patient adversary focused on maintaining access to critical infrastructure in a strategically important energy corridor.


Cybersecurity firm Bitdefender documented the intrusion with moderate-to-high confidence and shared findings with security researchers. The campaign underscores a critical lesson for defenders: patching vulnerabilities alone is insufficient without comprehensive credential rotation, access revocation, and detection of established persistence mechanisms.


## The Threat


The unnamed Azerbaijani energy company became the target of a relentless cyber espionage operation that unfolded in three distinct waves of attack. Each wave featured different payloads and techniques, but all exploited the same initial entry point—a vulnerability in Microsoft Exchange Server known as ProxyNotShell (a chain combining CVE-2021-41349 and CVE-2021-42821).


What distinguishes this campaign from typical one-off intrusions is its adaptive, multi-wave nature. Rather than establishing initial access and moving on, the threat actors repeatedly returned to the compromised network, swapping payloads, attempting new techniques, and establishing redundant footholds. This behavior indicates not opportunistic cybercriminals, but a disciplined, well-resourced threat actor operating under strategic directives.


"This intrusion should not be viewed as an isolated compromise, but as a sustained and adaptive operation conducted by an actor that repeatedly sought to regain and extend access within the victim environment," Bitdefender stated in its analysis.


## Geopolitical Context: Why Azerbaijan Matters Now


The timing and targeting of this intrusion carries significant geopolitical weight. Azerbaijan has emerged as a critical player in European energy security following two major developments:


1. Russia's gas transit agreement expiration (2024): After Russia ended its natural gas transit through Ukraine in January 2024, European markets pivoted to alternative suppliers, with the Southern Gas Corridor (which transits through Azerbaijan) becoming increasingly strategic for European energy independence.


2. 2026 Strait of Hormuz disruptions: Recent regional instability affecting global oil markets has elevated Azerbaijan's importance as an alternative supply route not dependent on Middle Eastern chokepoints.


This geopolitical backdrop is critical context. China's interest in Azerbaijani energy infrastructure is not coincidental—it reflects Beijing's broader strategy to monitor and potentially influence European energy markets, as well as securing supply chain intelligence for strategic planning.


## Technical Details: The ProxyNotShell Exploitation Chain


The attackers gained initial access by exploiting ProxyNotShell, a vulnerability affecting Microsoft Exchange Server that allows unauthenticated remote code execution. Despite being patched by Microsoft and widely known in security circles, the vulnerability remained unpatched on the target organization's infrastructure—a critical failure in asset management and patch compliance.


The exploitation chain follows a predictable pattern:

  • Reconnaissance: Identify vulnerable Exchange servers
  • Initial access: Exploit ProxyNotShell to execute arbitrary code
  • Web shell deployment: Establish a persistent foothold via web-accessible upload directories
  • Lateral movement: Spread within the network to broaden access and identify high-value targets
  • Payload delivery: Deploy backdoors for long-term persistence and command execution

  • ## Three-Wave Attack Timeline


    Wave One: Late December 2025


    The first intrusion, detected around December 25, 2025, resulted in the deployment of Deed RAT (also known as Snappybee), a sophisticated backdoor descended from the notorious ShadowPad malware. Deed RAT is widely used by multiple Chinese state-sponsored groups and enables remote command execution, lateral movement, and data exfiltration.


    The attackers employed an evolved DLL side-loading technique as their delivery mechanism. Rather than simply replacing a legitimate DLL file, the malicious loader specifically targeted LogMeIn Hamachi's legitimate binary. The technique overrides two specific exported functions within the malicious library, creating a two-stage trigger mechanism that executes the Deed RAT loader through the host application's normal control flow. This approach is significantly more sophisticated than basic DLL side-loading and helps evade endpoint detection and response (EDR) tools.


    Wave Two: Late January / Early February 2026


    Nearly a month after the first intrusion, the threat actors returned with a different payload: TernDoor, a backdoor that emerged in recent years targeting telecommunications infrastructure in South America. This payload swap suggests the attackers were either testing new tools, responding to detection of Deed RAT, or maintaining redundancy in their access mechanisms.


    In this second wave, the actors attempted to deploy TernDoor using a shellcode loader called Mofu Loader, previously attributed to another Chinese threat group (GroundPeony). The deployment was unsuccessful, but the attempt itself reveals tactical flexibility and resource-sharing among China's cyber operations infrastructure.


    Wave Three: Late February 2026


    The third and final documented wave, in late February 2026, saw the return of Deed RAT—but in a modified version. This updated variant used "sentinelonepro[.]com" for command-and-control communications and incorporated refined evasion techniques. The repeated deployment of Deed RAT variants suggests confidence in the tool's effectiveness despite potential detection.


    ## Malware Arsenal and Evolution


    ### Deed RAT (Snappybee)


    Deed RAT represents a mature evolution of ShadowPad, maintaining the core capabilities that made its predecessor attractive to Chinese espionage groups:

  • Remote command execution
  • Credential theft and lateral movement support
  • File manipulation and exfiltration
  • Anti-forensics capabilities

  • The DLL side-loading technique used to deliver Deed RAT is particularly noteworthy. By leveraging the legitimate LogMeIn Hamachi binary, the attackers created a supply chain-like exploitation that allows the malicious payload to execute within the security context of a trusted application. This significantly complicates endpoint detection.


    ### TernDoor


    Less publicly documented than Deed RAT, TernDoor emerged in South American telecommunications targeting in 2024. Its deployment against this Azerbaijani target suggests expanded geographic focus for this tool. TernDoor's capabilities likely include similar backdoor functionality, though specific features remain under-documented in public security research.


    ## Defensive Failures and Persistent Access


    The most damning aspect of this intrusion is what it reveals about the target organization's security posture:


  • Unpatched critical vulnerability: ProxyNotShell patches were available months before this intrusion. The vulnerability's presence indicates inadequate patch management.
  • Insufficient credential rotation: Despite detecting and removing the initial intrusion, the organization failed to comprehensively rotate compromised credentials, allowing re-exploitation using the same access path.
  • Lateral movement not contained: The attackers successfully moved laterally through the network, indicating inadequate network segmentation.
  • Redundant persistence: The organization's removal of the first backdoor did not prevent re-entry because sufficient persistence mechanisms remained in place.

  • This failure pattern—detecting an intrusion, removing visible malware, but failing to comprehensively eliminate adversary access—is depressingly common and exactly what sophisticated threat actors exploit.


    ## HackWire Analysis


    This campaign illustrates a sobering reality about state-sponsored cyber operations: patience and resource availability often matter more than advanced 0-day exploits. FamousSparrow repeatedly attacked the same target across a three-month period using a vulnerability that was months old and widely known. This wasn't sophistication born of technical prowess—it was sophistication born of persistence, resources, and the confidence that the target organization would make critical mistakes in remediation.


    The incident also reveals the inadequacy of "detect and remove" incident response against determined nation-state actors. Organizations frequently treat intrusion response as a discrete event—find the backdoor, remove the malware, restore normal operations. But sophisticated adversaries don't operate in discrete events; they establish multiple footholds, prepare fallback access mechanisms, and maintain persistence through compromised credentials and dormant payloads.


    The geopolitical context is equally important. This isn't random targeting of critical infrastructure—it's strategic targeting of an energy supplier that has become increasingly important to European energy security. The pattern suggests Chinese intelligence operations are systematically mapping supply chain vulnerabilities and establishing surveillance capabilities across infrastructure that could influence Beijing's strategic interests.


    For defenders, the implications are stark: patch urgency must be based not just on vulnerability severity but on the strategic importance of your organization and sector. An Azerbaijani oil company wasn't compromised because the attackers developed a sophisticated new exploit—it was compromised because a well-known vulnerability remained unpatched. That should alarm every critical infrastructure organization operating in a geopolitically sensitive sector.


    — HackWire Editorial


    ## Implications for Organizations


    This campaign carries lessons extending far beyond one Azerbaijani company:


    For Critical Infrastructure Operators

  • Assume breach from day one: Design security architecture assuming adversaries have initial access
  • Implement zero-trust network segmentation: Limit lateral movement capability even if initial compromise occurs
  • Establish comprehensive credential rotation procedures: Detected intrusions should trigger immediate, organization-wide credential resets

  • For Patch Management Teams

  • Prioritize vulnerabilities affecting critical infrastructure and internet-facing systems
  • Track vulnerability exploitation timelines: ProxyNotShell's widespread exploitation should have triggered urgent patching
  • Implement continuous patch auditing to identify gaps

  • For Geopolitically Sensitive Organizations

  • Threat modeling should incorporate state-sponsored targeting likelihood
  • Enhance detection and monitoring for tools known to be used by relevant nation-state groups
  • Coordinate with government cybersecurity agencies to share threat intelligence

  • ## Recommendations


    Organizations concerned about similar targeting should implement these defensive measures:


    1. Immediate patch verification: Audit all internet-facing servers for unpatched ProxyNotShell vulnerabilities

    2. Credential audit and rotation: Assume compromise of all administrative credentials; rotate across the environment

    3. Lateral movement detection: Deploy network monitoring and EDR solutions capable of detecting DLL side-loading and credential propagation

    4. Behavioral monitoring: Establish baselines for legitimate system behavior; alert on anomalous process execution and network connections

    5. Incident response planning: Develop procedures that go beyond malware removal to include comprehensive access elimination

    6. Supply chain awareness: Monitor supply chain tools (like LogMeIn) for potential abuse in your environment


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)