# TA488 OWAReaper Outlook Web Access exploit

> Live situation record from CLSTR: https://clstr.news/situations/ta488-owareaper-outlook-web-access-exploit
> Updated: 2026-07-31T03:53:03.000Z. Sources: 9. Developments: 2.

In late July 2026, the Russia‑aligned cyber‑espionage group TA488 (also known as Laundry Bear or Void Blizzard) was observed exploiting a critical cross‑site scripting flaw (CVE‑2026‑42897) in Microsoft Outlook Web Access. The “half‑click” exploit required only opening a crafted email, allowing the group to install the OWAReaper backdoor, which persists in the browser session and retains Owner‑level permissions even after password changes or device re‑imaging. The campaign, first reported on July 22, targeted government agencies, telecoms, financial services, hospitality and aerospace firms across the United States and Europe. Microsoft had disclosed the vulnerability in May and issued a patch in June, but the exploit was active before the public fix.

A follow‑up report the next day reiterated the same exploit chain, confirming that TA488 had been abusing the flaw since May 2026. While the focus remained on the OWAReaper threat, the report also noted a separate cloud‑based data breach at biotech firm Amgen attributed to the ShinyHunters group, underscoring a broader rise in sophisticated cyber‑attacks on enterprise and healthcare systems.

## Timeline

### 2026-07-31: Microsoft OWA Exploit and Amgen Data Breach Signal Growing Cyber Threats

New OWAReaper exploit targets Microsoft Outlook Web Access via CVE‑2026‑42897, while Amgen reports a cloud breach stealing patient data, highlighting rising cyber threats.

2 sources. https://clstr.news/cluster/microsoft-owa-exploit-and-amgen-data-breach-signal-growing-cyber-threats

### 2026-07-30: TA488 exploits Outlook Web Access zero‑day, adds OWAReaper backdoor

Russia‑linked TA488 used a half‑click OWA zero‑day (CVE‑2026‑42897) to install the persistent OWAReaper backdoor, targeting US and European organisations; Microsoft has patched the flaw and admins should revoke

8 sources. https://clstr.news/cluster/ta488-exploits-outlook-web-access-zeroday-to-install-owareaper-backdoor

---
Cite as: TA488 OWAReaper Outlook Web Access exploit. CLSTR, https://clstr.news/situations/ta488-owareaper-outlook-web-access-exploit
