Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months
ID: 03e8b104-8053-5385-ab3d-497715db2a1c
STIX ID: report--03e8b104-8053-5385-ab3d-497715db2a1c
Feed Name: The Hacker News
Unknown attackers quietly maintained roughly five months of access to a senior executive's Outlook mailbox at a major global stock exchange, using a mailbox-stealer built on the Aspose .NET library to convert OST/PST files and exfiltrate incremental mailbox exports via Dropbox and OneDrive; they deployed SYSTEM-level binaries, credential-dumping tools, FRPC tunneling, and scheduled-task persistence to blend activity with normal cloud traffic and avoid detection, with activity observed from Oct 2025 through Mar 2026 and a staged backdoor found in March.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
