logo

Cyber espionage campaign targeted stock exchange executive’s Outlook account

ID: f2a83ad1-88a6-5636-9b77-00111a41640c

STIX ID: report--f2a83ad1-88a6-5636-9b77-00111a41640c

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-06-03

Date Updated: 2026-06-04

Author: Pierluigi Paganini

...
...

**Executive summary:** Attackers maintained covert access to a senior stock exchange executive's Outlook mailbox from October 2025 to March 2026, using an Aspose-based extractor to convert OST files into incremental PST archives and exfiltrating small batches via Dropbox and OneDrive Personal; persistence was achieved through scheduled tasks and masquerading binaries, and the operation appears technically disciplined and likely state-linked despite no firm attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.