Global Stock Exchange Hit by Monthslong Email Campaign
A global stock exchange was targeted by a sophisticated threat actor who gained near-continuous access to a senior executive’s Microsoft Outlook mailbox over a five-month period. The attacker utilized legitimate Windows tools and stealthy techniques to steal emails containing sensitive organizational information, including contacts, calendar events, and business deals. This incident highlights the importance of proactive security measures, such as CASBs and EDR solutions, to prevent similar targeted attacks.
The attack, uncovered by Symantec and Carbon Black, involved a threat actor meticulously infiltrating the email inbox of a high-ranking executive at a global stock exchange. Beginning around August 2025, the attacker gained persistent access, utilizing techniques like lateral movement from a previously compromised device and deploying disguised software (Adobe and OneDrive) to establish a foothold. The attacker then employed a legitimate .NET library from Aspose to convert emails into local files for exfiltration via Dropbox. The attacker repeatedly stole the target’s entire email inbox roughly every two to four weeks, at least until February 17, 2026.
Researchers observed the attacker establishing a command-and-control channel via Dropbox and deploying a custom infostealer. The meticulous nature of the attack, including the use of a Lenovo system health check, demonstrated a deep understanding of the target's environment. The incident concluded in March 2026 with the deployment of new backdoors, after which the attacker lost access to the compromised device.
Cybersecurity experts emphasize the importance of proactive defenses. Utilizing CASBs and DLP solutions, along with actively monitoring alerts generated by EDR software, could have detected and prevented the data exfiltration. This case underscores the potential value of sensitive information held by exchanges and regulators, and the risks associated with targeted espionage campaigns.
