Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Stock Exchange Executive’s Email Hacked for Months

Stock Exchange Executive’s Email Hacked for Months

Posted on June 4, 2026 By CWS

In a significant cyber espionage incident, hackers infiltrated the Outlook mailbox of a senior executive at a leading global stock exchange for over five months, according to a report by Symantec and Carbon Black’s Threat Hunter Team. The attackers stealthily extracted inbox contents using cloud services such as Dropbox and OneDrive to mask their activities among regular network traffic.

Methodical Espionage Operation

Revealed earlier this week, the attack appears driven by intelligence gathering rather than financial theft, as detailed by Symantec. The attackers accessed the executive’s mailbox, potentially exposing sensitive information like non-public listing details, market strategies, and private communications, which could influence market dynamics.

Initial malicious activity was detected on October 10, 2025, when attackers had already established control over the target system. They utilized two binaries operating at the highest Windows privilege level, posing as updates from Adobe and OneDrive. The precise method of the initial system breach remains unknown, though Symantec suggests lateral movement from a previously compromised device.

Stealthy Data Exfiltration

The operation intensified on November 12, 2025, with the hackers leveraging a Dropbox API token and utilizing the ‘curl’ command for data uploads. The primary tool was a mailbox stealer based on the Aspose .NET library, which converted and exported Outlook mailbox files. The attackers returned repeatedly every few weeks to capture new data, avoiding detection by mimicking regular system tasks and utilizing personal cloud storage for exfiltration.

To further blend in, the attackers connected to hard-coded Microsoft IP addresses, bypassing DNS lookups that could trigger security alerts. They also tested other public file hosting services but eventually focused on Dropbox and OneDrive for their exfiltration activities.

Unresolved Attribution and Defense Measures

The incident remains unattributed, with generic tools and consumer cloud services obscuring clear links to any known hacking groups. The attackers employed various tools for traffic tunneling and credential dumping, but the lack of specific identifiers leaves the responsible party unknown.

Security experts emphasize the importance of monitoring for unusual mailbox activities and data transfers to personal cloud accounts. Organizations, especially those dealing with market-sensitive information, are advised to integrate threat indicators and remain vigilant against similar tactics.

This breach underscores the ongoing challenges in cybersecurity where traditional patches offer no solution. Instead, robust monitoring and response strategies are crucial to protecting valuable information assets.

The Hacker News Tags:cloud services, cyber attack, cyber espionage, Cybersecurity, data breach, Dropbox, email security, Hacking, IT security, Malware, OneDrive, Outlook mailbox, stock exchange, Symantec report, threat intelligence

Post navigation

Previous Post: Critical Flaw in Cisco Unified CM Exposes Systems to Exploits
Next Post: TA4922 Cyber Group Expands Global Operations Rapidly

Related Posts

Global Crypto Scam Crackdown: 276 Arrests, 1M Seized Global Crypto Scam Crackdown: 276 Arrests, $701M Seized The Hacker News
OAuth Consent: The New Phishing Threat Bypassing MFA OAuth Consent: The New Phishing Threat Bypassing MFA The Hacker News
Obsidian Plugin Exploitation Delivers PHANTOMPULSE RAT Obsidian Plugin Exploitation Delivers PHANTOMPULSE RAT The Hacker News
Italy Fines Apple €98.6 Million Over ATT Rules Limiting App Store Competition Italy Fines Apple €98.6 Million Over ATT Rules Limiting App Store Competition The Hacker News
Malicious NuGet Package Targets Financial Sector Malicious NuGet Package Targets Financial Sector The Hacker News
China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Southeast Asia China-Linked Amaranth-Dragon Exploits WinRAR Flaw in Southeast Asia The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • TA4922 Cyber Group Expands Global Operations Rapidly
  • Stock Exchange Executive’s Email Hacked for Months
  • Critical Flaw in Cisco Unified CM Exposes Systems to Exploits
  • Fake Open-Source Tool Sites Exploit Google Rankings for Malware
  • Cisco Alerts on PoC for Critical Unified CM Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • TA4922 Cyber Group Expands Global Operations Rapidly
  • Stock Exchange Executive’s Email Hacked for Months
  • Critical Flaw in Cisco Unified CM Exposes Systems to Exploits
  • Fake Open-Source Tool Sites Exploit Google Rankings for Malware
  • Cisco Alerts on PoC for Critical Unified CM Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark