Stock Exchange Executive’s Outlook Account Targeted in Credential Theft Attack
ID: 6d5d6dc3-1253-50f3-bb94-b7eb00ce3029
STIX ID: report--6d5d6dc3-1253-50f3-bb94-b7eb00ce3029
Feed Name: Cyber Press
Threat Score
**Executive summary:** A highly targeted espionage campaign (Oct 2025–early 2026) compromised a senior executive at a major stock exchange by installing a custom Aspose-based mailbox stealer that converted OST to PST and exfiltrated incremental email archives via Dropbox API and OneDrive; attackers achieved SYSTEM privileges, persisted with a deceptive scheduled task, and left multiple file-hash IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
