Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Stock Exchange Executive’s Email Hacked for Months

Stock Exchange Executive’s Email Hacked for Months

Posted on June 4, 2026 By CWS

In a significant cyber espionage incident, hackers infiltrated the Outlook mailbox of a senior executive at a leading global stock exchange for over five months, according to a report by Symantec and Carbon Black’s Threat Hunter Team. The attackers stealthily extracted inbox contents using cloud services such as Dropbox and OneDrive to mask their activities among regular network traffic.

Methodical Espionage Operation

Revealed earlier this week, the attack appears driven by intelligence gathering rather than financial theft, as detailed by Symantec. The attackers accessed the executive’s mailbox, potentially exposing sensitive information like non-public listing details, market strategies, and private communications, which could influence market dynamics.

Initial malicious activity was detected on October 10, 2025, when attackers had already established control over the target system. They utilized two binaries operating at the highest Windows privilege level, posing as updates from Adobe and OneDrive. The precise method of the initial system breach remains unknown, though Symantec suggests lateral movement from a previously compromised device.

Stealthy Data Exfiltration

The operation intensified on November 12, 2025, with the hackers leveraging a Dropbox API token and utilizing the ‘curl’ command for data uploads. The primary tool was a mailbox stealer based on the Aspose .NET library, which converted and exported Outlook mailbox files. The attackers returned repeatedly every few weeks to capture new data, avoiding detection by mimicking regular system tasks and utilizing personal cloud storage for exfiltration.

To further blend in, the attackers connected to hard-coded Microsoft IP addresses, bypassing DNS lookups that could trigger security alerts. They also tested other public file hosting services but eventually focused on Dropbox and OneDrive for their exfiltration activities.

Unresolved Attribution and Defense Measures

The incident remains unattributed, with generic tools and consumer cloud services obscuring clear links to any known hacking groups. The attackers employed various tools for traffic tunneling and credential dumping, but the lack of specific identifiers leaves the responsible party unknown.

Security experts emphasize the importance of monitoring for unusual mailbox activities and data transfers to personal cloud accounts. Organizations, especially those dealing with market-sensitive information, are advised to integrate threat indicators and remain vigilant against similar tactics.

This breach underscores the ongoing challenges in cybersecurity where traditional patches offer no solution. Instead, robust monitoring and response strategies are crucial to protecting valuable information assets.

The Hacker News Tags:cloud services, cyber attack, cyber espionage, Cybersecurity, data breach, Dropbox, email security, Hacking, IT security, Malware, OneDrive, Outlook mailbox, stock exchange, Symantec report, threat intelligence

Post navigation

Previous Post: Critical Flaw in Cisco Unified CM Exposes Systems to Exploits
Next Post: TA4922 Cyber Group Expands Global Operations Rapidly

Related Posts

GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection The Hacker News
Hackers Exploit Apache HTTP Server Flaw to Deploy Linuxsys Cryptocurrency Miner Hackers Exploit Apache HTTP Server Flaw to Deploy Linuxsys Cryptocurrency Miner The Hacker News
Learn How Leading Security Teams Blend AI + Human Workflows (Free Webinar) Learn How Leading Security Teams Blend AI + Human Workflows (Free Webinar) The Hacker News
Supply Chain Attacks Target PyTorch Lightning for Credential Theft Supply Chain Attacks Target PyTorch Lightning for Credential Theft The Hacker News
Uncover LOTS Attacks Hiding in Trusted Tools — Learn How in This Free Expert Session Uncover LOTS Attacks Hiding in Trusted Tools — Learn How in This Free Expert Session The Hacker News
MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & More MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & More The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Vulnerability in Mirasvit Cache Warmer Exposed
  • China-Linked TA4922 Broadens Cyber Attacks Globally
  • CISA Alerts on Critical Android Vulnerability Being Exploited
  • TA4922 Cyber Group Expands Global Operations Rapidly
  • Stock Exchange Executive’s Email Hacked for Months

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Vulnerability in Mirasvit Cache Warmer Exposed
  • China-Linked TA4922 Broadens Cyber Attacks Globally
  • CISA Alerts on Critical Android Vulnerability Being Exploited
  • TA4922 Cyber Group Expands Global Operations Rapidly
  • Stock Exchange Executive’s Email Hacked for Months

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark