Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacker... deployed the main tool: a mailbox stealer built on Aspose, a legitimate .NET library that reads Outlook OST and PST files.
During this initial entry period, the attackers focused their efforts entirely on quiet, persistent Outlook mailbox theft.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used as the core of an OST mailbox theft tool to read and convert Outlook offline storage files for staged exfiltration of the victim’s mailbox.
A custom mailbox-stealing tool built around the legitimate Aspose .NET library to parse Outlook OST/PST files, convert OST mailboxes into PST archives, and exfiltrate mailbox contents incrementally over time.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.