Stock Exchange Executive Mailbox Espionage — Five-Month Intrusion via Masquerading SYSTEM Binaries (armsvc.exe / oneservice.exe), Aspose-Based OST Theft, and Dropbox/OneDrive C2 & Exfiltration — Threadlinqs Intelligence
As of 2026-06-03, Stock Exchange Executive Mailbox Espionage — Five-Month Intrusion via Masquerading SYSTEM Binaries (armsvc.exe / oneservice.exe), Aspose-Based OST Theft, and Dropbox/OneDrive C2 & Exfiltration is a high-severity apt threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 46 indicators of compromise.
Threat ID: TL-2026-0672 · Severity: HIGH · Status: ACTIVE · Category: APT
Symantec/Broadcom documented a disciplined, five-month espionage intrusion that stole the Outlook mailbox of a senior executive at a major global stock exchange, exfiltrating it in incremental
Symantec's Threat Hunter Team disclosed a long-running, operationally disciplined espionage operation that compromised the host of a senior executive at a major global stock exchange and exfiltrated the executive's Outlook mailbox over roughly five months. The objective was pure intelligence collection — the executive's external negotiations, internal deliberations, calendar, travel patterns, and contacts — the kind of non-public, market-moving information an exchange holds about listings, enforcement actions, and corporate events. No ransomware, destruction, or lateral movement was needed; sustained mailbox access alone satisfied the objective.
When Symantec first observed activity on 10 October 2025, the attackers already held SYSTEM-level access: two masquerading binaries — armsvc.exe (path CSIDL_COMMON_APPDATA\adobe\arm\armsvc.exe, posing as the legitimate Adobe Acrobat Reader update service) and oneservice.exe (path CSIDL_PROFILE\appdata\local\microsoft\onedrive\setup\oneservice.exe, posing as a OneDrive setup helper) — were running as SYSTEM, each spawned by wininit.exe under the Service Control Manager. Local privilege escalation had therefore been achieved before the first observed activity (UAC bypass tooling, bypassuac.exe, was later seen on the host). Persistence was reinforced with high-frequency scheduled tasks masquerading as vendor maintenance jobs: an Adobe 'ARM Service' task firing every five minutes, OneDrive sync tasks every three minutes, and Lenovo 'CheckServerHealth' tasks at varying multi-hour intervals (300/900/1440 minutes) that launched batch files (c:\windows emp\1.bat through 5.bat) and redirected output to matching .txt files.
The campaign entered its active phase on 12 November 2025 with an OAuth handshake that obtained a Dropbox API token, followed by the first Outlook OST extraction. The attackers used Aspose — a legitimate commercial .NET library for parsing Outlook OST/PST files — invoked as c:\windows emp\Aspose.exe with a password (-p), the target OST (-f), an output directory (-o), and crucially a date-range flag (-t) such as 20250819-20251112. Subsequent runs narrowed the windows (20251112-20251121, 20251120-20251209, 20251209-20251216, and so on) at roughly two-to-four-week intervals through the final extraction on 17 February 2026, deliberately chunking the mailbox into small batches to stay under data-transfer and detection thresholds.
Command-and-control and exfiltration were built entirely on trusted public cloud services. A single persistent Dropbox application (constant client_id/client_secret, rotating per-session authorization codes) received uploads via curl POST to content.dropboxapi.com/2/files/upload with a Bearer token obtained from api.dropbox.com/oauth2/token. From 20-21 November the attackers added a OneDrive Personal channel (onedrive.live.com/personal/... _api AddUsingPath uploads) and briefly experimented with the public file-host temp.sh (51.91.79.17:443). To suppress telltale DNS lookups, the OneDrive channel was later switched to hard-coded Microsoft IP addresses 13.107.137.11 and 150.171.41.11. BeaconBeagle returned no matches for any network indicator — consistent with deliberate living-off-trusted-cloud tradecraft that leaves no dedicated C2 infrastructure to fingerprint.
Late in the campaign the attackers refreshed their toolset and persistence anchors: onedrivesync.exe (CSIDL_COMMON_APPDATA\microsoft onedrive\setup\onedrivesync.exe) was added as a persistence binary on 27 February 2026, and a previously unseen armdriver.exe (CSIDL_COMMON_APPDATA\adobe\arm\ondemand\armdriver.exe) plus te.host.dll (installed in CSIDL_COMMON_APPDATA\intel) appeared on 19 March 2026, the date of final observed activity. The mailbox-stealer payload itself was redeployed under rotating temp names (ts_9ea0.tmp, ts_e0d5.tmp, ts_e2d5.tmp — all sharing one SHA256) from CSIDL_WINDOWS emp and nested skin/licenses subfolders. Public/offensive tooling observed on the host included curl.ex
Target sectors: financial, financial-markets, stock-exchange, critical-infrastructure
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 46 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1583, T1059, T1053, T1053, T1543, T1543, T1548, T1036, T1036, T1562