Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

RussianTA488 Returns With Persistent Outlook Web Access Attack

July 29, 2026

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

July 29, 2026

LogoKit Phishing Kit Screenshots Victim Sites in Real Time

July 29, 2026
Facebook X (Twitter) Instagram
Wednesday, July 29
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»RussianTA488 Returns With Persistent Outlook Web Access Attack
News

RussianTA488 Returns With Persistent Outlook Web Access Attack

Team-CWDBy Team-CWDJuly 29, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A Russia-aligned espionage group has resurfaced after months without observed activity, using a half-click exploit against on-premises Outlook Web Access (OWA) to plant a browser-resident implant and establish server-side persistence that can survive credential rotation and device re-imaging.

According to new research from Proofpoint published on July 29, TA488, also tracked as Void Blizzard and Laundry Bear, began the campaign on July 22, one day before the company’s joint advisory with the NSA and partner agencies on the group’s earlier Zimbra activity. It had not been seen since February.

Targets spanned US and European government entities plus the telecommunications, financial, hospitality and aerospace sectors. The volume was unusual for the group, which Proofpoint suggested may have been deliberate to blend into mass-mailing spam.

Read more on TA488 activity: Russian Hackers Exploit New ‘Zero-Click’ Attack Against Western Organizations

Banal Lures, No Clicks Required

The messages exploited CVE-2026-42897, a cross-site scripting flaw affecting on-premises Exchange Server, not Exchange Online.

Opening the email in a vulnerable OWA client caused the victim’s browser to execute the embedded JavaScript within their authenticated session.

Lures were deliberately unremarkable, with subject lines covering semiconductor supply chains, gas markets and tourism metrics.

Proofpoint said the banality was likely deliberate, so the recipient opened and skimmed the message, then dismissed it as junk without reporting it, leaving no suspicious links or attachments to flag.

Persistence That Outlives the Device

The payload was OWAReaper, a previously unknown JavaScript implant Proofpoint called the most sophisticated half-click backdoor it has seen. It built on ZimReaper from the group’s Zimbra campaigns, dropping that tool’s mass email exfiltration.

OWAReaper ran entirely in the OWA reading pane with no conventional file on disk. It rewrote the original email on the server to strip the exploit, harvested saved credentials, then hid an encrypted copy of itself in browser localStorage under a legitimate OWA settings key, so every new tab re-executed it.

Its most durable mechanism was server-side: where add-ins with mailbox write permissions existed, it stole OAuth tokens and granted Exchange’s low-privilege Default user Owner-level permissions on every mail folder, opening the mailbox to any authenticated account in the organization.

It also planted a hidden iframe in messages held in OWA’s offline IndexedDB cache, which re-infected the target even after the host was re-imaged. Because the folder-permission grant lived server-side and required deliberate removal from Exchange, credential rotation and re-imaging did not evict the actor.

Two Command Channels, Two Exfiltration Routes

Commands arrived via GitHub commit messages, queried daily, or inbound emails polled every five minutes. Exfiltration occurred over HTTPS, proxied through legitimate image content delivery networks, with a fallback to DNS tunneling.

The campaign’s infrastructure dates to March 2026, roughly two months before Microsoft disclosed the flaw, making zero-day use feasible, though registration dates alone don’t confirm when exploitation began. Microsoft has since released Exchange security updates addressing the flaw.

Beyond patching, Proofpoint urged defenders to revoke Exchange Web Services tokens, strip Default-user folder grants and clear OWA’s offline database and localStorage key.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Team-CWD
  • Website

Related Posts

News

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

July 29, 2026
News

LogoKit Phishing Kit Screenshots Victim Sites in Real Time

July 29, 2026
News

Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories

July 29, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Why the tech industry needs to stand firm on preserving end-to-end encryption

September 12, 2025

How it preys on personal data – and how to stay safe

October 23, 2025

Children and chatbots: What parents should know

January 23, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.