Minacce · 140 giorni fa
Il rischio reale qui non è un singolo compromesso di Exchange. È un percorso di accesso che ha continuato a sopravvivere alla pulizia, consentendo agli attaccanti di tornare ogni volta con nuovi backdoor. Una risposta standard del tipo rimuovi-il-malware-e-patch-una-volta manca il fatto che il foothold stesso potrebbe essere ancora utilizzabile o essere stato ristabilito prima che la vittima lo chiudesse completamente.
4 fonti che coprono questa storia
Chinese APTs Expand Targets, Update Backdoors in Recent Campaigns
Salt Typhoon has hit an energy entity in Azerbaijan.
Bitdefender uncovers FamousSparrow attacks on Azerbaijan energy sector using DLL sideloading, and Deed RAT malware.
Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation
FamousSparrow reused ProxyNotShell from Dec 2025-Feb 2026, deploying Deed RAT and TernDoor to sustain energy-sector access.
China's 'FamousSparrow' APT Nests in South Caucasus Energy Firm
The cyberthreat group targets an Azerbaijani oil-and-gas firm with repeated attack, as the China-linked actors extend targeting beyond hotels and telcos.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-05-15