
Russian state-sponsored hackers affiliated with TA488, also known as Laundry Bear and Void Blizzard, are actively exploiting a critical vulnerability in Microsoft Outlook’s Exchange Server to compromise victims and exfiltrate sensitive data, according to security researchers at Proofpoint.
The vulnerability, designated CVE-2026-42897, is a cross-site scripting flaw that Microsoft provided mitigation guidance for in May and released a patch for in July. The vulnerability allows attackers to deliver malicious JavaScript code through email to Outlook Web Access accounts, requiring only that a user open the message to trigger compromise. Researchers indicated that TA488 may have exploited this vulnerability as a zero-day before the patch became available.
Upon successful exploitation, the attackers deploy a custom-built malware implant called OWAReaper, which Proofpoint describes as the most sophisticated backdoor ever delivered through this type of attack vector. The implant operates entirely within the Outlook Web Access interface and establishes persistent access by creating encrypted copies of itself in browser storage using legitimate system keys. The malware harvests user credentials through browser autofill mechanisms and can extract OAuth tokens, potentially granting access to other mailboxes on the same network.
A significant concern identified by researchers is that the compromised access persists on the server side and survives standard remediation attempts. Credential rotation and complete reimaging of affected devices will not remove the attacker’s access, requiring deliberate server-side remediation instead. Proofpoint has released recommendations for affected organizations, including auditing Exchange Web Services tokens, removing default folder permissions, clearing specific local storage keys, and monitoring for outbound connections to known command-and-control servers.
The disclosure follows a joint warning issued earlier by Proofpoint and the National Security Agency regarding the same threat group’s exploitation of a zero-day vulnerability in Zimbra email services, indicating an escalation in the group’s operational capabilities and sophistication.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI