Hackers Spied on a Stock Exchange Executive's Outlook Mailbox for Five Months
An unknown attacker gained unauthorized access to the Outlook mailbox of a senior executive at a major stock exchange for over five months, copying the inbox in small batches and utilizing cloud services like Dropbox and OneDrive to mask their activity. The operation, characterized by lateral movement and the use of tools like Aspose and FRPC, highlights the risk of espionage targeting individuals with access to sensitive market information. This incident underscores the importance of continuous monitoring and response for organizations handling confidential data.
The incident, reported by Symantec and Carbon Black's Threat Hunter Team, began on October 10, 2025, and involved a sustained campaign of espionage against a stock exchange executive’s Outlook mailbox. The attacker leveraged SYSTEM privileges to gain full control of the executive’s machine, likely originating from a previously compromised device. The attacker utilized a mailbox stealer built on Aspose, a legitimate .NET library, to convert the mailbox data into PST files and exfiltrate it through Dropbox and OneDrive, blending the traffic with normal cloud activity. The attacker’s tactics included mimicking legitimate system services like Adobe and OneDrive, and using hard-coded Microsoft IP addresses to avoid DNS lookups.
The attacker’s activity was methodical, executing multiple data pulls over a period of approximately five months, from August 2025 to February 17, 2026. The operation was characterized by a focus on gathering information related to the exchange’s operations, including listing details, enforcement matters, deal terms, and market-moving plans. The final observed activity, on March 19, 2026, involved staging a new backdoor that was never executed, suggesting the attacker’s access was subsequently lost. The incident highlights the potential for attackers to exploit individual access rather than targeting vulnerabilities in systems, emphasizing the need for robust user monitoring and access control policies.
This incident is particularly concerning due to the lack of attribution and the use of readily available tools. The attacker employed a wider intrusion kit, including FRPC for tunneling traffic, Secretsdump for credential dumping, and SharpDecryptPwd for recovering saved app passwords. The reliance on consumer cloud services like Dropbox and OneDrive, a tactic Microsoft has previously flagged, further complicates attribution efforts. Organizations handling sensitive information should proactively monitor for unusual mailbox export activity, odd Outlook access, and uploads to personal cloud accounts.
