← Back to news

Hackers Target Global Stock Exchange in Espionage Operation

SecurityWeek03/06/2026, 12:46
Read full article →

Summary

AI-Generated

Key Points:

  • Hackers targeted a senior executive's email account at a major global stock exchange, exfiltrating data over a period of approximately five months.
  • The attack, which began in October 2025 and lasted until March 2026, allowed the threat actor to gather sensitive information without lateral movement, posing significant risks to the organization’s confidentiality and operational integrity.
  • Organizations should enhance monitoring of executive email accounts and implement strict access controls. Regular audits of user activity and anomaly detection measures are recommended to identify potential breaches early.

Technical Details: The initial access vector remains unknown, but malware disguised as legitimate applications (Adobe and OneDrive) was detected on the compromised host. Command-and-control channels were established using Dropbox and OneDrive for data exfiltration.

MITRE ATT&CK Techniques:

  • T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
  • T1059.001 - Command and Scripting Interpreter: PowerShell (Execution)
  • T1547.001 - Boot or Logon Autostart Execution: Registry Run Keys (Persistence)

IOCs Mentioned:

  • None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.