FamousSparrow Linked to Multi-Wave Intrusion Targeting Azerbaijani Oil and Gas Company
Check the threat actor activity and update monitoring.
Check security posture and update intrusion detection rules.
Summary
A threat actor affiliated with China, known as FamousSparrow (UAT-9244), carried out a multi-wave intrusion against an unnamed Azerbaijani oil and gas company from late December 2025 to late February 2026. The attack involved multiple stages of compromise, indicating a coordinated effort to gain persistent access. Bitdefender attributed the activity with moderate-to-high confidence, noting that the group has expanded its targeting scope. The intrusion spanned more than two months, suggesting a long‑term campaign rather than a single opportunistic breach. No specific compromise details were disclosed, but the extended timeline points to a sophisticated threat actor. The incident highlights the growing risk to critical infrastructure sectors in the region.
Key changes
- Multi‑wave intrusion spanned Dec 2025–Feb 2026.
- Targeted unnamed Azerbaijani oil and gas company.
- Attributed to FamousSparrow (UAT‑9244).
- Expansion of targeting scope noted by Bitdefender.
- Attack involved multiple stages of compromise.
- No specific compromise details disclosed.
- Indicates sophisticated threat actor.
- Highlights risk to critical infrastructure.