Skip to main content
Mallory
Back to intelligence
data-exfiltration-methodstate-sponsored-espionagepersistence-methodcredential-access-method

Espionage Intrusion Stole Stock Exchange Executive’s Outlook Mailbox via Cloud Exfiltration

Updated 6h agoFirst seen Jun 3, 20264 sources

Researchers at Symantec and Carbon Black said unknown attackers maintained access for about five months to the Outlook mailbox of a senior executive at a major global stock exchange, quietly collecting email data from late 2025 into early 2026. The intruders used a custom mailbox-stealing tool built around the legitimate Aspose .NET library to convert the victim’s OST data into PST archives and repeatedly export the mailbox in small, date-bounded batches, indicating a deliberate intelligence-gathering operation rather than smash-and-grab theft.

The stolen mailbox data was exfiltrated through Dropbox and OneDrive Personal to blend into ordinary cloud traffic, while persistence was hidden behind scheduled tasks and binaries masquerading as Adobe, Lenovo, and OneDrive components. Investigators also found tooling linked to tunneling, credential dumping, password recovery, and UAC bypass, along with hard-coded Microsoft IP addresses used to avoid OneDrive DNS lookups; attribution and the initial access vector remain unknown, but the incident shows how a single compromised executive mailbox can expose negotiations, calendars, contacts, travel plans, and other potentially market-sensitive information.

Share:
Espionage Intrusion Stole Stock Exchange Executive’s Outlook Mailbox via Cloud Exfiltration
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jun 4, 20267h ago

Attackers deploy new malware components in March 2026

The espionage campaign targeting the stock exchange executive remained active through March 2026, when the attackers introduced new malware components. This indicated the intrusion was still ongoing and adaptive beyond the previously observed mailbox collection period ending in mid-February.

Stock Exchange Executive’s Outlook Account Targeted to Exfiltrate Credentials

Researchers disclose espionage campaign targeting stock exchange executive

Broadcom's Symantec and Carbon Black threat-hunting team publicly reported a suspected intelligence-gathering intrusion in which attackers maintained roughly five months of access to a senior stock exchange executive's Outlook mailbox. The researchers said attribution remained unresolved and assessed the activity as espionage rather than financially motivated theft.

Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months

Researchers publish IOCs for stock exchange executive intrusion

Alongside reporting on the espionage intrusion, Symantec and Carbon Black released indicators of compromise for the malware and persistence mechanisms used in the attack. The disclosure included details such as scheduled-task persistence masquerading as Lenovo and OneDrive services and other disguised components to aid detection.

Stock exchange executive’s Outlook mailbox stolen over course of 5 months | news | SC Media
Feb 17, 20264mo ago

Observed mailbox collection activity continues through mid-February

Periodic mailbox collection from the compromised executive account continued for months as part of a long-running espionage operation. Symantec said the observed collection phase ran through February 17, 2026.

Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months
Nov 12, 20257mo ago

Mailbox theft phase begins against executive Outlook account

The attackers began repeatedly exporting the executive's Outlook mailbox in small, date-bounded batches using a mailbox-stealing tool built on the legitimate Aspose .NET library. The stolen data was exfiltrated via Dropbox and OneDrive Personal to blend into normal cloud traffic.

Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months
Oct 10, 20258mo ago

Attackers first gain foothold in stock exchange executive intrusion

Symantec and Carbon Black observed the first malicious activity tied to the espionage intrusion targeting a senior executive at a major global stock exchange. The initial access vector was not determined.

Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

17 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.