#OWAReaper
So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb?

Well...

We kinda lied

Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper

www.proofpoint.com/us/blog/thre...
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
www.proofpoint.com
July 29, 2026 at 9:12 AM
The excitement continues. @greg-l.bsky.social discovered Russia-aligned actor TA488 using another half-click exploit - this time in Outlook- leading to a new (very cool) browser-based implant, OWAReaper. Check out TA488 upping its game @threatinsight.proofpoint.com www.proofpoint.com/us/blog/thre...
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
www.proofpoint.com
July 29, 2026 at 9:10 AM
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper.
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper.
www.bleepingcomputer.com
July 29, 2026 at 11:44 PM
Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
The OWAReaper implant can establish server-side mailbox permissions that remain after credentials are changed and affected devices are rebuilt.
www.csoonline.com
July 30, 2026 at 11:42 AM
Russian group Laundry Bear drops the OWAReaper backdoor when users just view emails in OWA. Because rotating credentials was far too simple.

#sameoldowa #patchdayagain
July 31, 2026 at 11:17 AM
TA488 exploits CVE-2026-42897 in Microsoft Exchange/OWA to deliver OWAReaper, gaining persistent access and stealing credentials from unpatched systems.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
July 31, 2026 at 2:42 PM
We trained users not to click the link.

Russia found a workaround: just open the email.

OWAReaper changes the rules of phishing, persistence, and incident response.

jimguckin.com/2026/08/11/y...

#Cybersecurity #Infosec
You Trained Them Not to Click, and Russia Found a Way Around That – Jim Guckin
Jim Guckin: security leadership, practitioner writing, and 20+ years of being in the room when things went wrong.
jimguckin.com
August 12, 2026 at 12:00 PM
📢 CVE-2026-42897 : TA488 exploite une XSS stockée dans Exchange OWA via l'implant OWAReaper

Cet article constitue une analyse technique approfondie de la vulnérabilité CVE-2026-42897 et de la campagne d'exploitation associée…

🟢 vérification factuelle haute
#ExchangeOWA #OWAReaper #Cyberveille
CVE-2026-42897 : TA488 exploite une XSS stockée dans Exchange OWA via l'implant OWAReaper
Cet article constitue une analyse technique approfondie de la vulnérabilité CVE-2026-42897 et de la campagne d'exploitation associée menée par le groupe TA488 (également connu sous les noms Void Blizzard et Laundry Bear), acteur étatique russe.
cyberveille.ch
September 4, 2026 at 4:30 PM
Cyber Threat Exploits Outlook Web Access Flaw to Deploy OWReaper Mail Implant

Discover how an advanced threat actor exploits an Outlook Web Access flaw to deploy the OWReaper mail implant to compromise enterprise communications.
Read the full threat analysis: www.ampcuscyber.com/shadowopsint...
TA488 OWAReaper Outlook Malware Attack Explained
Learn how TA488 uses OWAReaper to exploit Outlook Web Access, steal credentials, and maintain persistent email access across organizations.
www.ampcuscyber.com
August 19, 2026 at 12:17 PM
Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
RussianTA488 Returns With Persistent Outlook Web Access Attack
TA488 returned with OWA half-click exploit deploying OWAReaper implant that survived re-imaging
www.infosecurity-magazine.com
August 5, 2026 at 12:12 AM
August 3, 2026 at 5:37 PM
# **Falla in Outlook: apri un’e-mail e ti infettano, non servono più link o allegati**

@informatica
Il gruppo criminale filorusso TA488 sfrutta la CVE-2026-42897, falla XSS in Outlook Web Access, con un exploit half-click: basta aprire l'email per installare OWAReaper, una backdoor che […]
Original post on poliverso.org
poliverso.org
August 3, 2026 at 12:37 PM
📰 Hacker Rusia Eksploitasi Zero-Day Exchange OWA untuk Mempertahankan Akses ke Kotak Email Korban

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/08/03/zero-day-exchange-owa-owareaper-rusia/

#apt
##apta#keamananSibera#malwareo#microsoftExchangeo#outlookWebAccess##owaa#rusia-#zero
August 3, 2026 at 6:52 AM
Daily IT Security Digest — 2026-08-03
— Stealthy Outlook Exploit Targets Email Accounts

The APT group TA488 is distributing OWAReaper, a stealthy exploit targeting Microsoft Outlook that grants attackers persistent inbox access without any user interaction. A malicious email triggers the attack
August 3, 2026 at 5:02 AM
TA488、OWAReaperによるOutlookエクスプロイトでパスワードを迂回

目に見えない侵入 悪意のあるリンクも不審な添付ファイルも一切含まない、まったくありふれたメール。それだけで、悪名高いハッカー集団TA488は被害者の受信箱への永続的なアクセスを確保するのに十分でした。あとは、疑いを抱かない利用者がOutlookのWebインターフェースでそのメッセージを開くのを、じ...
TA488、OWAReaperによるOutlookエクスプロイトでパスワードを迂回
目に見えない侵入 悪意のあるリンクも不審な添付ファイルも一切含まない、まったくありふれたメール。それだけで、悪名高いハッカー集団TA488は被害者の受信箱への永続的なアクセスを確保するのに十分でした。あとは、疑いを抱かない利用者がOutlookのWebインターフェースでそのメッセージを開くのを、じ
blackhatnews.tokyo
August 3, 2026 at 3:47 AM
Aktive Kampagne von TA488 nutzt XSS-Schwachstelle in Outlook Web Access. OWAReaper-Implantat stiehlt Zugangsdaten und bleibt trotz Passwortwechsel bestehen.
Outlook-Lücke CVE-2026-42897: TA488 nutzt XSS aktiv aus
borncity.com
August 2, 2026 at 3:35 AM
*** Exploiting Outlook Web Access Zero-Day: New 'Half-Click' Attack Deploys OWAReaper Malware ***
Exploiting Outlook Web Access Zero-Day: New 'Half-Click' Attack Deploys OWAReaper Malware...

www.hissenit.com/en/blog/it-s...

#phishing #scorm #lms #cybersecurity #awareness #training
August 1, 2026 at 9:55 AM
OWAReaper lives in the browser, not the host, so credential rotation and re-imaging do nothing. It re-infects from IndexedDB, phones home via GitHub commit search, and grants itself Owner on every mailbox it touches. IT teams are cleaning the wrong layer.
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Russian hackers exploit CVE-2026-42897 in OWA to deploy OWAReaper, a browser implant that persists through credential rotation and device re-imaging.
thehackernews.com
July 31, 2026 at 8:53 PM
Russian operators are exploiting an Outlook Web Access flaw to keep reading mail after a password change. Opening the email is enough. Re-imaging the device will not evict them. The fix has to happen on the Exchange server.
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Russian hackers exploit CVE-2026-42897 in OWA to deploy OWAReaper, a browser implant that persists through credential rotation and device re-imaging.
thehackernews.com
July 31, 2026 at 7:30 PM
Laundry Bear's new backdoor survives credential resets & system reinstalls. Impressive tradecraft, or just another reminder that email remains cybersecurity's favorite punching bag? Either way: patch your OWA. 🔐
https://bit.ly/4yIYh6J
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper.
bit.ly
July 31, 2026 at 3:30 PM
Just another Tuesday as Laundry Bear deploys the OWAReaper backdoor via an OWA XSS flaw, CVE-2026-42897, triggered by a mere half-click on malicious emails. Naturally, government, telecom, finance, aerospace, and hospitality outfits across North America and Europe get to suffer t...

Read full story
July 31, 2026 at 11:17 AM