
Russian state-sponsored hackers affiliated with the Kremlin are actively exploiting a critical vulnerability in Microsoft Exchange Server to compromise unpatched systems and extract sensitive data, according to findings announced Thursday by security researchers at Proofpoint.
The attacks are attributed to TA488, a group also known as Laundry Bear and Void Blizzard that operates on behalf of the Russian government. This marks the second major campaign by the group in recent weeks, following a similar operation using a zero-day flaw in Zimbra’s email service that was jointly disclosed by Proofpoint and the National Security Agency last week. The group’s deployment of increasingly sophisticated techniques signals a notable advancement in its capabilities and operational sophistication.
The vulnerability, identified as CVE-2026-42897, is classified as a cross-site-scripting flaw stemming from inadequate HTML filtering in emails. Microsoft provided mitigation guidance in May and released a patch in July after assigning it a maximum severity rating. The exploit works through a “half-click” mechanism, meaning users need only open a malicious email in Outlook Web Access to trigger compromise. Upon activation, the vulnerability executes malicious JavaScript code that installs a custom-built backdoor named OWAReaper.
OWAReaper represents a significant technical advancement in browser-based attack methods. The backdoor operates entirely within the Outlook Web Access interface and employs multiple persistence mechanisms. It harvests user credentials by leveraging the browser’s autofill functionality, captures OAuth tokens to gain broader network access, and stores encrypted copies of itself in the browser’s local storage using legitimate Outlook configuration keys. Crucially, the backdoor persists on the Exchange server itself, meaning that standard remediation steps such as credential changes or device re-imaging will not remove the threat.
Proofpoint has recommended that affected organizations revoke and audit their Exchange Web Services tokens, remove default user folder permissions, clear relevant local storage keys, and block connections to identified command-and-control servers. The extent to which Microsoft’s July patch addresses previously compromised systems remains unclear.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI