Episode
This Sparrow doesn't migrate. [Research Saturday]
- Podcast
- CyberWire Daily
- Published
- Jun 13, 2026
- Duration seconds
- 1368
- Processing state
not_requested- Canonical source
- https://thecyberwire.com/podcasts/research-saturday/429/notes
Actions
POST https://stenobird.com/v1/public/podcasts/cyberwire-daily-454880/episodes/this-sparrow-doesn-t-migrate-research-saturday/transcription-requests
Idempotently request low-priority transcript generation for this episode.GET https://stenobird.com/podcast/cyberwire-daily-454880/this-sparrow-doesn-t-migrate-research-saturday.md
Read the agent-friendly Markdown representation of this episode resource.
Summary
Martin Zugec, Technical Solutions Director at Bitdefender, discussing their work on "FamousSparrow APT Targets Azerbaijani Oil and Gas Industry." Bitdefender researchers uncovered a sustained cyber espionage campaign by the China-linked FamousSparrow group targeting an Azerbaijani oil and gas company, highlighting the growing focus on critical energy infrastructure in the South Caucasus. The attackers repeatedly exploited the same vulnerable Microsoft Exchange server over multiple months, deploying evolving versions of Deed RAT and Terndoor malware through sophisticated DLL sideloading techniques designed to evade detection and maintain persistence. The operation underscores FamousSparrow's adaptability and persistence, demonstrating how advanced threat actors continually refine their tooling and return to compromised environments until vulnerabilities are fully remediated and access is cut off. The research and executive brief can be found here: FamousSparrow APT Targets Azerbaijani Oil and Gas Industry Learn more about your ad choices. Visit megaphone.fm/adchoices