TA488 exploits Outlook Web Access zero‑day to install OWAReaper backdoor
Russian‑aligned threat group TA488 (also known as Void Blizzard, Laundry Bear) launched a campaign on July 22, 2026 that weaponised the newly disclosed Outlook Web Access (OWA) cross‑site scripting vulnerability CVE‑2026‑42897. The “half‑click” exploit required only opening a crafted email in OWA, triggering malicious JavaScript that installed a browser‑resident implant called OWAReaper. The backdoor stores an encrypted copy in the browser’s localStorage, modifies OWA’s offline message cache and obtains Owner‑level Exchange folder permissions, allowing it to persist through credential resets and device re‑imaging.
Proofpoint identified the activity and reported that the campaign targeted government, telecommunications, finance, hospitality and aerospace organisations across the United States and Europe. The group used lure messages about supply chains, energy and public‑health topics to increase the likelihood of opening. Microsoft issued an emergency patch shortly after the vulnerability was made public and later released permanent updates for supported Exchange versions. The exploit highlights ongoing risks from zero‑day flaws in on‑premises Exchange deployments.
Entities: Microsoft · OWAReaper · Outlook Web Access · Proofpoint · TA488