security-com · Crawled Jul 31, 2026

Espionage Campaign Targeted Stock Exchange Executive for Five Months

19 IoCs
Read original article ↗

AI Summary

A five-month espionage campaign targeted the Outlook mailbox of a senior executive at a major global stock exchange, using masqueraded binaries and legitimate cloud services for persistence and data exfiltration. The attackers achieved SYSTEM-level access and deployed a custom Aspose-based OST stealer to incrementally extract mailbox data, exfiltrating it in small batches via Dropbox and OneDrive Personal to avoid detection. The campaign demonstrated high operational discipline, leveraging scheduled tasks, IP-based OneDrive connections to evade DNS logging, and multiple file redeployments under different names but consistent hashes, indicating a focused, long-term intelligence collection effort.

AI-extracted · verify before operational use

Indicators of Compromise 19 extracted

Type Value Detail
SHA-256 db59813e3f27fb8608a4876e758f60b69d9700dc22d15237ac095bb3166fb622 Details →
SHA-256 6c700ca4e6d917c7aa9d964e98604a0349d9b8b4673df96a3f73a3d2d042635a Details →
IP 13[.]107[.]137[.]11 Details →
IP 150[.]171[.]41[.]11 Details →
IP 51[.]91[.]79[.]17 Details →
Filename ts_9ea0.tmp Details →
Filename ts_e0d5.tmp Details →
Filename ts_e2d5.tmp Details →
Filename armdriver.exe Details →
Filename onedrivesync.exe Details →
Filename armsvc.exe Details →
Filename oneservice.exe Details →
Filename ss.exe Details →
Filename sddsvc.exe Details →
Filename bypassuac.exe Details →
Filename sidehost.exe Details →
Filename sepservice.exe Details →
Filename appsvc.exe Details →
Filename te.host.dll Details →