Stock Exchange Executive’s Outlook Account Targeted in Credential Theft Attack

A senior executive at a major global stock exchange recently fell victim to a highly targeted, five-month-long espionage campaign designed to siphon sensitive communications quietly.

Rather than moving laterally across the corporate network, the threat actors focused solely on the executive’s Microsoft Outlook mailbox.

This singular focus provided the attackers with a wealth of intelligence, including external negotiations, market-moving events, and the executive’s daily calendar.

By camping in the email account from October 2025 through early 2026, the attackers built a comprehensive picture of the organization’s strategic direction.

The initial infection vector remains unknown, but researchers first observed malicious activity on October 10, 2025.

By this time, the attackers had already achieved local privilege escalation, running two masquerading binaries as SYSTEM. The first binary mimicked a legitimate Adobe Acrobat Reader update service.

In contrast, the second disguised itself within a local OneDrive setup folder. The attackers maintained persistent access by registering a five-minute scheduled task under a deceptive Microsoft Adobe-themed name, allowing them to remain undetected on the host machine.

Attack chain (Source: security)
Attack chain (Source: security)

Executive Outlook Credentials Targeted

The primary weapon in this campaign was a custom mailbox-stealing tool built on Aspose, a legitimate commercial .NET library used to parse Outlook data.

The attackers wrapped this library into a standalone executable that converted the executive’s Offline Storage Table (OST) files into Personal Storage Table (PST) formats.

To avoid triggering security alerts with massive data transfers, the malware extracted emails in small, incremental data chunks.

The attackers routinely renamed the stealer using temporary file extensions. They invoked it repeatedly to maintain a near-continuous flow of stolen communications.

For data exfiltration, the espionage group leveraged legitimate cloud infrastructure to blend in with normal network traffic.

They heavily utilized the Dropbox API, operating a persistent application and rotating only the per-session authorization codes to upload the stolen email archives.

Beginning in late November 2025, the attackers introduced a secondary exfiltration channel using OneDrive Personal.

To bypass DNS-based blocking and perimeter logging, they accessed OneDrive using hard-coded Microsoft IP addresses instead of the standard hostname.

Indicators of Compromise

IndicatorDescription
db59813e3f27fb8608a4876e758f60b69d9700dc22d15237ac095bb3166fb622Aspose-based Mailbox Infostealer (redeployed as ts_9ea0.tmp, ts_e0d5.tmp, ts_e2d5.tmp)
6c700ca4e6d917c7aa9d964e98604a0349d9b8b4673df96a3f73a3d2d042635ate.host.dll (installed in Intel staging directory)
1f385acf11f8ea6673d7295be6492ea9913b525da25dcc037ea49ef4f86a9d58SharpDecryptPwd
2587217bc685527480c803ddf34a56ae9d9bf02681828a8a2081acc775312cf3FRPC

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories