
Russian state-sponsored hackers affiliated with TA488, also known as Laundry Bear and Void Blizzard, are actively exploiting a critical vulnerability in Microsoft Outlook’s Exchange Server to compromise unpatched machines and extract sensitive data, according to security researchers at Proofpoint. The group has demonstrated an escalating capability by leveraging “half-click” exploits, which require users only to open a malicious email sent to an Outlook Web Access account to trigger compromise.
The vulnerability, designated CVE-2026-42897, is a cross-site-scripting flaw stemming from inadequate filtering of HTML content in emails. Microsoft provided mitigation guidance in May and released a patch in July, assigning the vulnerability a maximum severity rating. Researchers indicate that TA488 may have exploited the vulnerability prior to the official patch release. The flaw allows attackers to execute malicious JavaScript code within the email reading environment.
The malware delivered through this vulnerability is a previously unknown implant called OWAReaper, which researchers describe as the most sophisticated backdoor ever delivered via a half-click exploit. Upon execution, OWAReaper modifies the original email on the Exchange server to hide exploit content and harvests user credentials by intercepting autofill data. The backdoor then establishes persistence by embedding encrypted copies of itself within the browser’s local storage, positioning itself to execute automatically whenever the user accesses their OWA account.
A distinguishing characteristic of this attack chain is the persistence mechanism’s resistance to standard remediation efforts. Proofpoint noted that the backdoor access persists on the server side and cannot be removed through conventional methods such as credential rotation or complete device re-imaging. The malware can potentially harvest OAuth tokens, granting attackers comprehensive access to mailboxes across the network.
Security researchers are recommending that affected organizations revoke and audit Exchange Web Services tokens, remove default user folder permissions, clear specific local storage keys, and monitor for connections to identified command-and-control infrastructure. The extent to which Microsoft’s July patch eliminates existing infections remains unclear.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI