ctipilot.ch

FamousSparrow Azerbaijan intrusion

campaign · campaign:famoussparrow-azerbaijan-2026

FamousSparrow (UAT-9244) three-wave intrusion of an Azerbaijani oil & gas operator, December 2025 – February 2026: ProxyNotShell re-exploitation plus a novel two-stage export-gated DLL-sideloading chain.

Aliases: UAT-9244

Coverage timeline
1
first 2026-05-14 → last 2026-05-14
Peak priority
high
1 high
Sources cited
3
3 hosts
Sections touched
1
deep-dive
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
7
pinned v19.2 · see below

ATT&CK techniques

7 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-14/famoussparrow-three-wave-intrusion-of-an-azerbaijani-energy · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-05-14/famoussparrow-three-wave-intrusion-of-an-azerbaijani-energy · ATT&CK page ↗

Execution TA0002

T1059.001Command and Scripting Interpreter: PowerShell×1

Adversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code. Examples include the <code>Start-Process</code> cmdlet which can be used to run an executable and the <code>Invoke-Command</code> cmdlet which runs a command locally or on a remote computer (though administrator permissions are required to use PowerShell to connect to remote systems).

Evidence: 2026-05-14/famoussparrow-three-wave-intrusion-of-an-azerbaijani-energy · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-05-14/famoussparrow-three-wave-intrusion-of-an-azerbaijani-energy · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-14/famoussparrow-three-wave-intrusion-of-an-azerbaijani-energy · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-05-14/famoussparrow-three-wave-intrusion-of-an-azerbaijani-energy · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-14/famoussparrow-three-wave-intrusion-of-an-azerbaijani-energy · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-05-14/famoussparrow-three-wave-intrusion-of-an-azerbaijani-energy · ATT&CK page ↗

T1574.001Hijack Execution Flow: DLL×1

Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be simultaneously utilized by multiple programs. While DLLs are not malicious by nature, they can be abused through mechanisms such as side-loading, hijacking search order, and phantom DLL hijacking.

Evidence: 2026-05-14/famoussparrow-three-wave-intrusion-of-an-azerbaijani-energy · ATT&CK page ↗

Lateral Movement TA0008

T1021.001Remote Services: Remote Desktop Protocol×1

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.

Evidence: 2026-05-14/famoussparrow-three-wave-intrusion-of-an-azerbaijani-energy · ATT&CK page ↗

T1021.002Remote Services: SMB/Windows Admin Shares×1

Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.

Evidence: 2026-05-14/famoussparrow-three-wave-intrusion-of-an-azerbaijani-energy · ATT&CK page ↗

Story timeline

  1. 2026-05-14FamousSparrow Three-Wave Intrusion of an Azerbaijani Energy Operator: ProxyNotShell Re-exploitation and a Wave-1 DLL-Sideload Loader That Overrides Two Hamachi Exports to Defeat Sandbox Analysis
    deep-diveFamousSparrow Three-Wave Intrusion of an Azerbaijani Energy Operator: ProxyNotShell Re-exploitation and a Wave-1 DLL-Sideload Loader That Overrides Two Hamachi

Where this entity is cited

  • deep-dive1

Source distribution

  • bitdefender.com1 (33%)
  • github.com1 (33%)
  • thehackernews.com1 (33%)

explore in graph

Entries about FamousSparrow Azerbaijan intrusion (1)

2026-05-14 · view entry permalink →

HIGH

FamousSparrow Three-Wave Intrusion of an Azerbaijani Energy Operator: ProxyNotShell Re-exploitation and a Wave-1 DLL-Sideload Loader That Overrides Two Hamachi Exports to Defeat Sandbox Analysis

Background. FamousSparrow has been tracked publicly since 2021 as a China-nexus espionage cluster targeting hotels, government and engineering firms; Bitdefender's 2026-05-13 write-up cites tooling and infrastructure overlap with the Earth Estries cluster, and The Hacker News summary additionally notes Salt Typhoon overlap. Recent primary technical detail has been sparse — the Bitdefender Labs publication on 2026-05-13 is the first multi-wave intrusion case study against an energy-sector victim published in some time (Bitdefender Labs, 2026-05-13; The Hacker News, 2026-05-13). The Azerbaijan targeting is geopolitically novel for the cluster: Bitdefender characterises Azerbaijani gas-export expansion to 13 European countries (with new flows to Germany and Austria) following the post-Ukraine-transit reconfiguration, making extraction and transit infrastructure intelligence operationally valuable to Chinese state actors monitoring European energy supply dependencies.

Victim, time-frame, framing. Bitdefender Labs documented a three-wave intrusion against an unnamed Azerbaijani oil and gas operator spanning December 2025 to February 2026, attributed with moderate-to-high confidence to FamousSparrow (also tracked as UAT-9244 in Talos taxonomy). The operationally most consequential framing is not the attribution but the fact that all three waves re-used the same Exchange initial access vector despite the victim's attempted remediation — the structural lesson is patch-completeness verification rather than novel-zero-day defence.

Vulnerability mechanics & initial access. Initial access in every wave exploited the ProxyNotShell chain — CVE-2022-41040 (SSRF in the Exchange front-end Auto-discover handler) chained with CVE-2022-41082 (deserialisation in the back-end PowerShell remoting endpoint) against an on-premises Microsoft Exchange Server. The vulnerable surface is the front-end Exchange Autodiscover.svc accepting a crafted IIS request that triggers internal SSRF to the Mailbox role's PowerShell remoting endpoint; the deserialisation in the chained PowerShell context yields code execution under the Exchange application-pool identity (typically LocalSystem on the mailbox server). The re-exploitation across three waves indicates either incomplete cumulative-update application (Microsoft's HealthChecker.ps1 is the canonical verification harness) or a persistence foothold — likely a web shell or scheduled task — that survived clean-up rounds and re-armed the same vulnerable code path.

Exploitation chain mapped to ATT&CK. Each wave deployed distinct payload combinations on top of the same initial-access foothold:

  • T1190 Exploit Public-Facing Application — ProxyNotShell against Exchange (each wave).
  • T1505.003 Server Software Component: Web Shell — surviving persistence from an earlier wave is the most plausible explanation for re-exploitation across remediation attempts.
  • T1059.001 Command and Scripting Interpreter: PowerShell — Exchange PowerShell remoting deserialisation gadget yields PowerShell execution; subsequent reconnaissance and tooling drop.
  • Wave 1: Deed RAT (Snappybee) deployed via DLL sideloading against a signed LogMeIn Hamachi binary — Deed RAT is the ShadowPad successor lineage (encrypted C2, file I/O, command execution, process injection). The sideloading is the technique-novelty highlight: per Bitdefender the malicious DLL overrides two of Hamachi's exported functions (Init, ComMain) and patches StartServiceCtrlDispatcherW, so the payload only executes when Hamachi's own service-start path runs. T1574.002 Hijack Execution Flow: DLL Side-Loading is the ATT&CK umbrella, but the override-and-patch detail is what defeats sandbox harnesses: stub harnesses that call DllMain or a small set of obvious exports never trigger Init / ComMain in the right order and the payload stays dormant.
  • Wave 2: TernDoor deployed via DLL sideloading against a renamed-but-legitimate deskband_injector64.exe — Bitdefender records the second wave as introducing TernDoor as a second backdoor family. The sideloading host is deskband_injector64.exe renamed USOShared.exe and placed in C:\ProgramData\USOShared\; the malicious loader is winmm.dll in the same directory. (No legitimate Microsoft "USOShared" signed binary is involved — the directory name is reused for camouflage.)
  • Wave 3: Modified Deed RAT with updated C2 infrastructure — Bitdefender's third wave is an evolution of Wave 1's implant (refreshed C2, no novel sideloading host), confirming the operator's preference for iterating on the Deed RAT line rather than abandoning it.
  • T1078 Valid Accounts + T1021.001 RDP / T1021.002 SMB — lateral movement via Impacket, RDP, SMB tooling once the Exchange-server foothold is established.

Named clusters and shared tooling. Bitdefender's overlap assessment places FamousSparrow / UAT-9244 in operational relationship with Earth Estries (Trend Micro taxonomy); The Hacker News summary additionally connects the cluster to Salt Typhoon (Microsoft taxonomy). Implants observed include Deed RAT (Snappybee), TernDoor, Mofu Loader and ShadowPad ancestry; the LogMeIn Hamachi sideloading host is freshly observed for this cluster and indicates active tooling rotation rather than reuse of a known signed-binary host.

Detection and hunt concepts. Defender-actionable, behavioural — not IOCs:

  • Exchange patch-verification audit: Run Microsoft's HealthChecker.ps1 against every on-premise Exchange server and review the output for Exchange Build and Hotfix Applied lines. CU-level patch status alone is insufficient — the cumulative-update installer occasionally rolls back fixes if an OWA front-end customisation conflicts. Cross-reference IIS log analysis for repeated POST requests to /autodiscover/autodiscover.json with non-empty bodies, especially when the same external IP returns over a span of days — the ProxyNotShell exploitation pattern leaves this footprint.
  • Web-shell survival sweep: Audit the Exchange FrontEnd\HttpProxy\owa\auth\ and FrontEnd\HttpProxy\ecp\auth\ directories for files modified post-patch, and the Exchange transport-agents folder for unsigned scheduled tasks. Persistence outliving clean-up was the structural enabler of re-exploitation in this case.
  • LogMeIn Hamachi / signed-binary sideload anomalies: Hunt for hamachi*.exe or logmein*.exe loading DLLs from non-standard installation paths, or any legitimately signed binary whose child process tree spawns cmd.exe / powershell.exe with encoded arguments. The export-override gating makes the loader resilient against generic sandbox detection, but the eventual payload still spawns shell children — Sysmon event ID 1 with ParentImage filter on known signed binaries and CommandLine patterns for -EncodedCommand / -enc remains effective. Wave 2's sideloading is the same class of abuse using a renamed legitimate binary — extend the hunt to deskband_injector64.exe running from non-standard paths (Bitdefender placed it as C:\ProgramData\USOShared\USOShared.exe) and to any winmm.dll load from a ProgramData subdirectory rather than from the system search path.
  • DLL load-order anomaly hunt: T1574.002 sideloading depends on a writable DLL search path adjacent to the host binary. Hunt Sysmon event ID 7 (Image Load) records for the Hamachi process loading DLLs from %LOCALAPPDATA%\Temp\ or other writable user-context paths rather than from the legitimate Program Files\LogMeIn Hamachi\ install directory.
  • Lateral-movement signatures: alert on Impacket execution patterns (smbexec.py / wmiexec.py) — process command lines containing \\127.0.0.1\admin$ and Win32 service installations with randomly-named binaries (__output style) on member servers. RDP from Exchange servers to non-administrative workstations is anomalous regardless of source-account legitimacy.

Hardening / mitigation. Concrete configuration toggles, not advice:

  • Exchange: Apply the latest cumulative update and verify with HealthChecker.ps1; deploy Microsoft's mitigation script for ProxyNotShell-class URL rewriting if running an Exchange version still affected. Consider the broader move to Exchange Online for organisations that have not migrated — on-premises Exchange remains a top initial-access vector across China-nexus campaigns.
  • Application-allow-listing: Enforce Windows Defender Application Control (WDAC) or AppLocker policies that disallow LOLBin-style execution of logmein*.exe / hamachi*.exe from %TEMP% / %LOCALAPPDATA% paths. Even legitimately signed binaries should not run from user-writable directories.
  • EDR / Microsoft Defender for Endpoint: enable "Block executable content from email client and webmail" and "Block all Office applications from creating child processes" ASR rules; these do not directly catch the Hamachi sideload but harden adjacent ingress paths.
  • Conditional Access: Require modern-authentication and device-compliance for OWA / EAS / Outlook desktop where Exchange Online or hybrid mailboxes are in use; legacy authentication on hybrid setups continues to expose ProxyNotShell-adjacent paths.

Operationally critical context for Swiss / EU public-sector SOCs. Per Bitdefender, Azerbaijani gas exports now reach 13 European countries including Germany and Austria — so energy-sector intelligence collection against an Azerbaijani operator is structurally collection against the upstream end of European energy supply. The ProxyNotShell-re-exploitation pattern documented here is not Azerbaijan-specific — any organisation in CH / EU with an on-premise Exchange server that received CU patches but lacks HealthChecker.ps1-level verification carries the same exposure. The Wave-3 export-gated sideloading technique generalises to any legitimate signed binary an operator chooses to abuse; defenders should treat it as a class problem (DLL sideloading from signed hosts) rather than a Hamachi-specific signature.

threat14 May 05:00Zmulti-sourceOpen finding ↗