Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Stock Exchange Executive’s Email Hacked for Months

Stock Exchange Executive’s Email Hacked for Months

Posted on June 4, 2026 By CWS

In a significant cyber espionage incident, hackers infiltrated the Outlook mailbox of a senior executive at a leading global stock exchange for over five months, according to a report by Symantec and Carbon Black’s Threat Hunter Team. The attackers stealthily extracted inbox contents using cloud services such as Dropbox and OneDrive to mask their activities among regular network traffic.

Methodical Espionage Operation

Revealed earlier this week, the attack appears driven by intelligence gathering rather than financial theft, as detailed by Symantec. The attackers accessed the executive’s mailbox, potentially exposing sensitive information like non-public listing details, market strategies, and private communications, which could influence market dynamics.

Initial malicious activity was detected on October 10, 2025, when attackers had already established control over the target system. They utilized two binaries operating at the highest Windows privilege level, posing as updates from Adobe and OneDrive. The precise method of the initial system breach remains unknown, though Symantec suggests lateral movement from a previously compromised device.

Stealthy Data Exfiltration

The operation intensified on November 12, 2025, with the hackers leveraging a Dropbox API token and utilizing the ‘curl’ command for data uploads. The primary tool was a mailbox stealer based on the Aspose .NET library, which converted and exported Outlook mailbox files. The attackers returned repeatedly every few weeks to capture new data, avoiding detection by mimicking regular system tasks and utilizing personal cloud storage for exfiltration.

To further blend in, the attackers connected to hard-coded Microsoft IP addresses, bypassing DNS lookups that could trigger security alerts. They also tested other public file hosting services but eventually focused on Dropbox and OneDrive for their exfiltration activities.

Unresolved Attribution and Defense Measures

The incident remains unattributed, with generic tools and consumer cloud services obscuring clear links to any known hacking groups. The attackers employed various tools for traffic tunneling and credential dumping, but the lack of specific identifiers leaves the responsible party unknown.

Security experts emphasize the importance of monitoring for unusual mailbox activities and data transfers to personal cloud accounts. Organizations, especially those dealing with market-sensitive information, are advised to integrate threat indicators and remain vigilant against similar tactics.

This breach underscores the ongoing challenges in cybersecurity where traditional patches offer no solution. Instead, robust monitoring and response strategies are crucial to protecting valuable information assets.

The Hacker News Tags:cloud services, cyber attack, cyber espionage, Cybersecurity, data breach, Dropbox, email security, Hacking, IT security, Malware, OneDrive, Outlook mailbox, stock exchange, Symantec report, threat intelligence

Post navigation

Previous Post: Critical Flaw in Cisco Unified CM Exposes Systems to Exploits
Next Post: TA4922 Cyber Group Expands Global Operations Rapidly

Related Posts

Enhancing Windows Security: Tackling MFA and Credential Risks Enhancing Windows Security: Tackling MFA and Credential Risks The Hacker News
6 Steps to 24/7 In-House SOC Success 6 Steps to 24/7 In-House SOC Success The Hacker News
LLM Agent Exploitation Follows Marimo Vulnerability Attack LLM Agent Exploitation Follows Marimo Vulnerability Attack The Hacker News
OpenAI Bans ChatGPT Accounts Used by Russian, Iranian and Chinese Hacker Groups OpenAI Bans ChatGPT Accounts Used by Russian, Iranian and Chinese Hacker Groups The Hacker News
Czech Republic Blames China-Linked APT31 Hackers for 2022 Cyberattack Czech Republic Blames China-Linked APT31 Hackers for 2022 Cyberattack The Hacker News
New AI-Targeted Cloaking Attack Tricks AI Crawlers Into Citing Fake Info as Verified Facts New AI-Targeted Cloaking Attack Tricks AI Crawlers Into Citing Fake Info as Verified Facts The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO
  • Critical SharePoint Vulnerability CVE-2026-50522 Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Clover Health Reports Data Breach Impacting Customer Info
  • Zimbra Releases Fixes for Critical SNMP and XSS Flaws
  • Iranian APT42 Enhances Phishing Tactics with AI Technology
  • Andreas Gaetje: Journey from Economics to Körber CISO
  • Critical SharePoint Vulnerability CVE-2026-50522 Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark