Exchange Foothold Reused Across Three Intrusion Waves

The real risk here is not one Exchange compromise. It is an access path that kept surviving cleanup, letting the attackers come back with new backdoors each time. A standard remove-the-malware-and-patch-once response misses that the foothold itself may still be usable or was re-established before the victim fully closed it. Bitdefender ties FamousSparrow to three waves against an Azerbaijani oil-and-gas firm from late December 2025 through late February 2026. The same Microsoft Exchange entry point was reused after remediation attempts, with payloads shifting from Deed RAT to TernDoor and back to a modified Deed RAT. For Exchange operators, the lesson is that mailbox-server access can outlast partial cleanup and support repeat espionage, credential theft, and follow-on persistence. That is a bigger problem in energy-sector environments where externally reachable mail systems sit close to sensitive operational and corporate networks.

Part of the PlainSec briefing for 2026-05-15

Sources