Search...

Azerbaijan Government CERT investigates cyberattack activities targeting Azerbaijan’s energy sector by China-linked APT group

Azerbaijan Government CERT investigates cyberattack activities targeting Azerbaijan’s energy sector by China-linked APT group

It is alleged that the Chinese state-linked APT (Advanced Persistent Threat) group known as FamousSparrow conducted a multi-stage cyberattack against one of the companies operating in Azerbaijan’s oil and gas sector.

The Computer Emergency Response Center (Azerbaijan Government CERT) of the Special Communication and Information Security State Service of the Republic of Azerbaijan conducted indicator-based threat intelligence and technical investigations regarding the identified cyber threat activities.

According to the published news, the attackers allegedly gained initial access by exploiting the ProxyShell and ProxyNotShell vulnerabilities in Microsoft Exchange Server, subsequently established persistent access through the deployment of a web shell and later utilized DLL sideloading techniques to deploy the Deed RAT and TernDoor malware families on compromised systems.

Nevertheless, comprehensive technical analyses did not identify any evidence of “FamousSparrow” activity within the “AzStateNet” segment. Security assessments were conducted against file hashes, domains, URL addresses and other indicators of compromise associated with the reported attack vector, while potential signs of compromise were further evaluated through hash-based analysis. In addition, relevant queries related to the identified domain indicators were executed across the “AzStateNet” network infrastructure. As a result of the measures undertaken, preventive blocking actions were implemented based on the technical indicators associated with the alleged malicious activity and corresponding restrictions were enforced across the relevant security systems.

It is recommended that government entities investigate suspicious outbound connections and anomalous activities, promptly inform the relevant authorities if any signs of compromise are identified, conduct checks for the domains sentinelonepro[.]com:443 and virusblocker[.]it[.]com:443 and based on the obtained IOC indicators, perform retrospective and ongoing monitoring across relevant institutions, including indicator-based reviews of state email services, SIEM, EDR/XDR, firewall, proxy and DNS logs, as well as additional analysis of Microsoft Exchange infrastructure and authentication records.

The Center continues monitoring and threat intelligence activities aimed at protecting critical information infrastructures against cyber threats, ensuring the timely detection of potential attack activities and implementing preventive security measures.

 

You can find more detailed information in the Threat Intelligence report by downloading it.

© 2011-2026 All rights reserved