logo

Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months

ID: 03e8b104-8053-5385-ab3d-497715db2a1c

STIX ID: report--03e8b104-8053-5385-ab3d-497715db2a1c

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: [email protected] (The Hacker News)

...
...

Unknown attackers quietly maintained roughly five months of access to a senior executive's Outlook mailbox at a major global stock exchange, using a mailbox-stealer built on the Aspose .NET library to convert OST/PST files and exfiltrate incremental mailbox exports via Dropbox and OneDrive; they deployed SYSTEM-level binaries, credential-dumping tools, FRPC tunneling, and scheduled-task persistence to blend activity with normal cloud traffic and avoid detection, with activity observed from Oct 2025 through Mar 2026 and a staged backdoor found in March.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.