Espionage Campaign Targeted Stock Exchange Executive for Five Months
June 4, 2026, 8:40 a.m.
Description
Unknown attackers conducted a five-month espionage campaign against a senior executive at a major global stock exchange, systematically stealing the victim's Outlook mailbox in incremental batches. The attackers demonstrated sophisticated operational discipline by using legitimate cloud services like Dropbox and OneDrive Personal for exfiltration and command-and-control infrastructure. They employed an Aspose-based mailbox stealer to extract OST files in date-range windows, beginning with historical emails from August 2025 and continuing with regular two-to-four-week intervals through February 2026. The intrusion maintained persistence through masquerading binaries and scheduled tasks themed around legitimate Adobe and Lenovo services. By extracting mailbox data incrementally and routing traffic through trusted cloud platforms, the attackers avoided detection while building a comprehensive intelligence picture of the executive's communications and organizational activities.
Tags
Date
- Created: June 3, 2026, 12:55 p.m.
- Published: June 3, 2026, 12:55 p.m.
- Modified: June 4, 2026, 8:40 a.m.
Indicators
- 1f385acf11f8ea6673d7295be6492ea9913b525da25dcc037ea49ef4f86a9d58
- 8c0871cd0f60bc603424e948a689945a1828d0bef926a6470ae18cf17d93f7cb
- 22f335a65c479c26019f6187dae290624117c82a702a96acbb04fa325f730d3e
- 02048121fd0b3a51751ce7677155aa8818eba9d8ce67ea26fd1d7f43cfcdabd2
- 8b283c954d19a839a724961ccaf025c56988c4e745acb2d31a15a006cda072bf
- db59813e3f27fb8608a4876e758f60b69d9700dc22d15237ac095bb3166fb622
- d78f64551d1b31a31e5998e442f0debd458e011e05019b3951d9ddde997f8384
- f72a8b71f12eaab6518873f72ea4be4572d9f3fb8e8706ade3b9a7314f236f22
- eaff006ac0eb7f7fe4db5fc6a4b5b1dc272d83ced66d510dcea185b1278bb453
- d5e42104292513232d26ad7d9d317b5c779577da43e28fe27f8c2fb9318b0e8e
- cf731b82c471211938b210ae8a6dcc7ece4f44371e716f056fa05151a9910727
- 3aae5a24e63f3cb1ca4759b9e4ee8e503ff139189423f5fd8cc923c6819697ca
- 2587217bc685527480c803ddf34a56ae9d9bf02681828a8a2081acc775312cf3
- 6c700ca4e6d917c7aa9d964e98604a0349d9b8b4673df96a3f73a3d2d042635a
- 3b6cb20891bce8602ce669187754871e402a1782031ef8b032cd007e3894bc5d
- 611db3195d55e871dce67ce5c41e894bbaab88dd0d019af68f5a259f0108aef7
- 308351124c496d4f4effee65ab828506abf70385773c167ab1f32a7f030385ac
- c3405d9c9d593d75d773c0615254e69d0362954384058ee970a3ec0944519c37
- 6a69ea2ce3fea0ebfd7a32a1dfc4251bd4d7d8a4fbd44aaa47b82290d0414a9f
- acf5ed6e5bb90c44683938f35efeca551428064cdedbbaab8be69e3474fb806f
Additional Informations
- Finance