A senior executive at a major global stock exchange recently fell victim to a highly targeted, five-month-long espionage campaign designed to siphon sensitive communications quietly.
Rather than moving laterally across the corporate network, the threat actors focused solely on the executive’s Microsoft Outlook mailbox.
This singular focus provided the attackers with a wealth of intelligence, including external negotiations, market-moving events, and the executive’s daily calendar.
By camping in the email account from October 2025 through early 2026, the attackers built a comprehensive picture of the organization’s strategic direction.
The initial infection vector remains unknown, but researchers first observed malicious activity on October 10, 2025.
By this time, the attackers had already achieved local privilege escalation, running two masquerading binaries as SYSTEM. The first binary mimicked a legitimate Adobe Acrobat Reader update service.
In contrast, the second disguised itself within a local OneDrive setup folder. The attackers maintained persistent access by registering a five-minute scheduled task under a deceptive Microsoft Adobe-themed name, allowing them to remain undetected on the host machine.

Executive Outlook Credentials Targeted
The primary weapon in this campaign was a custom mailbox-stealing tool built on Aspose, a legitimate commercial .NET library used to parse Outlook data.
The attackers wrapped this library into a standalone executable that converted the executive’s Offline Storage Table (OST) files into Personal Storage Table (PST) formats.
To avoid triggering security alerts with massive data transfers, the malware extracted emails in small, incremental data chunks.
The attackers routinely renamed the stealer using temporary file extensions. They invoked it repeatedly to maintain a near-continuous flow of stolen communications.
For data exfiltration, the espionage group leveraged legitimate cloud infrastructure to blend in with normal network traffic.
They heavily utilized the Dropbox API, operating a persistent application and rotating only the per-session authorization codes to upload the stolen email archives.
Beginning in late November 2025, the attackers introduced a secondary exfiltration channel using OneDrive Personal.
To bypass DNS-based blocking and perimeter logging, they accessed OneDrive using hard-coded Microsoft IP addresses instead of the standard hostname.
Indicators of Compromise
| Indicator | Description |
|---|---|
db59813e3f27fb8608a4876e758f60b69d9700dc22d15237ac095bb3166fb622 | Aspose-based Mailbox Infostealer (redeployed as ts_9ea0.tmp, ts_e0d5.tmp, ts_e2d5.tmp) |
6c700ca4e6d917c7aa9d964e98604a0349d9b8b4673df96a3f73a3d2d042635a | te.host.dll (installed in Intel staging directory) |
1f385acf11f8ea6673d7295be6492ea9913b525da25dcc037ea49ef4f86a9d58 | SharpDecryptPwd |
2587217bc685527480c803ddf34a56ae9d9bf02681828a8a2081acc775312cf3 | FRPC |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.