Cyber espionage campaign targeted stock exchange executive’s Outlook account


Cyber espionage campaign targeted stock exchange executive’s Outlook account

Pierluigi Paganini
June 03, 2026

Attackers spent five months silently stealing emails from a stock exchange executive’s Outlook account in a suspected espionage operation.

A threat actor quietly sat inside a senior executive’s Outlook account at a major global stock exchange for roughly 150 days, from October 2025 to March 2026.

Espionage Campaign Targeted Stock Exchange

Broadcom’s Symantec and Carbon Black threat-hunting team investigated the incident and published their findings this week. They don’t name the exchange, and they don’t attribute the attack to any known threat actor.

By quietly monitoring the mailbox, attackers could collect sensitive information on negotiations, internal discussions, calendars, contacts, travel plans, and potentially market-moving events. Researchers highlighted the case because it shows how a single compromised executive account can provide a detailed picture of an organization’s activities without attackers needing to move elsewhere on the network.

“For an espionage actor, a senior executive’s mailbox is a high-value intelligence target. An Outlook profile may yield details of external negotiations, internal deliberations, the executive’s calendar, travel pattern, and their contacts.” reads the report published by Broad Symantec. “Organizations such as exchanges and regulators may hold non-public information about listings, enforcement actions and market-moving events. Months of unfettered access to that mailbox lets an attacker build a near-complete picture of the target’s working life and the organization’s near-term direction without ever having to move laterally elsewhere on the network.”

According to the researchers, attackers are not financially motivated, the compromise is part of an intelligence operation.

The first signs of malicious activity appeared on October 10, 2025, though how the attacker got in initially remains unknown. At that point, two malicious binaries were already running on the host with SYSTEM-level privileges, disguised as Adobe Acrobat and OneDrive processes. The attacker had already done the hard part before anyone was watching.

The operation turned active on November 12, when command-and-control channels came online and data started moving. The tool at the center of everything was a wrapper around Aspose, a legitimate commercial .NET library that can parse Outlook mailbox files. The attacker used it to convert the executive’s OST file into a PST archive and push it out in dated chunks, each covering a window of a few weeks.

“Eight further OST-extraction runs followed at roughly two-to-four-week intervals through to February 17, 2026, each time with a -t window that adjoined the previous one.” continues the report. “The cumulative effect over the five months observed is a complete, near-continuous theft of the user’s Outlook mailbox, broken into incremental archives small enough not to draw attention from security software.”

Exfiltration went through Dropbox and OneDrive Personal to avoid rising suspicion. Both are services that appear in normal corporate traffic every day. The attacker also hardcoded Microsoft IP addresses instead of hostnames for OneDrive calls, which neatly bypasses DNS-based logging. That’s not a rookie move.

Persistence was a constant concern. The attacker re-registered scheduled tasks every few weeks under names mimicking Adobe, Lenovo, and OneDrive services. The task intervals rotated between 5-minute, 5-hour, 15-hour, and 24-hour windows. Each new registration overwrote the previous one, keeping the footprint minimal. On February 27, a new binary appeared masquerading as the OneDrive sync service; on March 19, another disguised as an Adobe driver component. The attacker kept refreshing their grip on the machine all the way to the end.

The identity of whoever is behind this stays unknown. The use of public tools, cloud infrastructure for both C2 and exfiltration, and no reuse of infrastructure tied to known groups all make attribution very difficult. What’s clear is that the operation was tightly scoped, technically disciplined, and almost certainly state-linked given the target and the patience involved.

Symantec and Carbon Black have published the full list of indicators of compromise, including file hashes for the mailbox stealer and the various masquerading executables, at security.com. If you run endpoint detection for a financial institution, regulator, or anyone else sitting on market-sensitive information, those hashes are worth feeding into your tooling today.

“The attackers’ focus throughout was on a single objective: long-term, incremental theft of the contents of a single Outlook mailbox, exfiltrated through Dropbox and OneDrive Personal in small batches over a period of five months to avoid raising suspicions or triggering alerts on the system.” concludes the report. “This was a tightly focused and highly targeted campaign, with five months being a significant dwell time for an attacker. It is notable to see the different techniques and approaches used by the attacker in order to stay under the radar and maintain persistent access.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)







Source link

Leave a Reply

Subscribe to Our Newsletter

Get our latest articles delivered straight to your inbox. No spam, we promise.

Recent Reviews


Another week has passed, and Apex is still the top thriller on Netflix and the No. 1 movie in the streamer’s current top 10. Audiences are loving the cat-and-mouse battle between Charlize Theron’s rock climber and Taron Egerton’s serial killer. It will be interesting to see what movie inevitably knocks it down to second place.

If you’re searching for more thrillers, then you’ve come to the right place. Our top recommendation is the fifth entry into one of Hollywood’s iconic horror series. The other movies on this list include a little-seen survival thriller with an A-plus cast and a feature film adaptation of a post-apocalyptic novel. Stream all three of these movies on Netflix in the U.S.

3

Eden

Survival on the island

What the heck happened to Eden? The survival thriller premiered at the 2024 Toronto International Film Festival and entered limbo immediately after due to its lack of distribution. Nearly a year passed before Vertical finally released Eden in theaters on August 22, 2025. You would think that this movie had an easy sell—recognizable actors stuck on an island, with chaos ensuing. I’m still baffled as to why a major studio didn’t pick it up in the United States.

Eden is inspired by true events surrounding the residents of Floreana Island in the 1930s. Dr. Friedrich Ritter (Jude Law) leaves Germany and moves to Floreana Island with Dore Strauch (Vanessa Kirby). They are eventually joined by Margret Wittmer (Sydney Sweeny), Heinz Wittmer (Daniel Brühl), and Eloise Bosquet de Wagner Wehrhorn (Ana de Armas). Tensions rise as the competing families vie for control of the island, resulting in fatal decisions that lead to multiple tragedies. Eden certainly has some Lord of the Flies elements in its story.

Again, I’m shocked this movie was dumped in August instead of receiving a traditional rollout from a popular studio. Admittedly, Eden has its flaws and heavily leans into melodrama much to its detriment. Still, it’s an entertaining thriller supported by a stacked cast that is much better than it’s given credit for.​​​​​​​

2

Leave the World Behind

Technology becomes the villain

What would happen if the collapse of technology led to the end of the world? That’s part of the premise of Leave the World Behind, Sam Esmail’s 2023 psychological thriller for Netflix. The movie is based on Rumaan Alam’s novel of the same name. Right when an oil tanker crashes on the shore, something is not right in Leave the World Behind.

Amanda Sandford (Julia Roberts) is on vacation with her husband Clay (Ethan Hawke) and two children when inexplicable occurrences, like the oil tanker crash, begin happening. The root of the issue is a nationwide blackout that has caused widespread panic. Amanda and Clay are forced to grapple with their trust issues after the arrival of the vacation home’s owner, George H. “G.H.” Scott (Mahershala Ali), and his daughter, Ruth (Myha’la).

Some may view Leave the World Behind as a warning to humanity, which feels ill-equipped to handle a devastating cyberattack. Others might watch strictly for its entertainment purposes. I fell somewhere in the middle. There are some relevant messages about the apocalypse, social inequality, and societal standards. It’s also a great cast of talented performers who elevate the source material. I don’t think the film depicts what actually would happen in a disaster, but it’s certainly fun (and scary) to predict the future. ​​​​​​​

1

Scream

I would like to play another game

To clarify, I’m referring to 2022’s Scream, informally known as Scream V. It’s a nightmare scenario for anyone like myself, who has to write an article about the fifth Scream installment. For bookkeeping purposes, I’m calling it Scream V. Part of the reason for the similar title to the first movie is because Scream V restarted the franchise after an 11-year hiatus. It’s not a reboot or a remake, but a continuation of the series.

The film opens with a similar sequence to 1996’s Scream, where an unsuspecting high school student, Tara Carpenter (Jenna Ortega), is attacked by a new Ghostface killer in Woodsboro. Tara’s half-sister, Sam (Melissa Barrera), returns to town and learns that Tara’s friend group is now being targeted by Ghostface. If you’re dealing with Ghostface, there’s only one person to call for help: Sidney Prescott (Neve Campbell), who has survived the killer’s multiple attempts at her life.

​​​​​​​

I was surprisingly impressed with Radio Silence’s take on Scream. These reboots are typically cash grabs and a way for studios to exploit the IP of a popular entity. Scream V plays the hits—close calls, gory kills, and a propensity for dark humor. For me, it works as one of the franchise’s best entries. I thought Scream was done following Scream 4. Now, you’re probably going to get Scream VIII in a few years.


​​​​​​​More Netflix movies to watch

Two new Netflix movies, My Dearest Assassin and Remarkably Bright Creatures, arrive at week’s end just in time for the weekend. You can also stream classic Oscar-winning movies, including Roma and Glory. No matter what you choose, chances are you’ll be occupied for the foreseeable future with Netflix content.

Subscription with ads

Yes, $8/month

Simultaneous streams

Two or four




Source link