
Kremlin-affiliated hackers tracked as TA488 are actively exploiting a critical vulnerability in Microsoft Exchange Server to compromise unpatched machines and steal sensitive information, according to security researchers who disclosed the threat Thursday.
Proofpoint and the National Security Agency jointly warned of TA488’s activities, also known by the tracking names Laundry Bear and Void Blizzard. The group previously exploited a zero-day vulnerability in Zimbra email services using similar attack methods. The discovery that TA488 is now leveraging the Exchange Server flaw demonstrates an evolution in the group’s operational sophistication and technical capabilities. The attacks require minimal user interaction, with compromise occurring when a target simply opens a malicious email sent to an Outlook Web Access account.
The vulnerability, designated CVE-2026-42897, is a cross-site-scripting flaw that stems from inadequate filtering of HTML content in emails. Microsoft provided mitigation guidance in May and released a patch in July, assigning it maximum severity status. Researchers determined that TA488 likely exploited the vulnerability before the patch became available. Once triggered, the malicious code executes a custom-built browser extension called OWAReaper, which establishes persistent access to compromised OWA accounts.
OWAReaper operates within the OWA reading pane and automatically executes each time the user accesses their email through a browser. The malware captures credentials, session keys, and authentication tokens while concealing its presence by disabling interface elements. Notably, the backdoor stores itself on the Exchange server itself, meaning that standard remediation measures such as password changes or device re-imaging will not remove it. Attackers can subsequently harvest OAuth tokens to access email accounts across the victim’s network infrastructure.
Proofpoint has advised affected organizations to revoke and audit Exchange Web Services tokens, remove unauthorized folder permissions, clear specific local storage keys, and monitor for connections to identified command-and-control server domains. The extent to which Microsoft’s published patch or emergency mitigation service eliminates existing infections remains uncertain.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI