#TA488
Excited to share I'm presenting a last-minute talk @virusbtn.bsky.social! Come watch me hype @greg-l.bsky.social's research on Russia-aligned TA488's operational evolution, complete with half-click XSS exploits, zero-days, webmail stealers, & browser implants www.virusbulletin.com/conference/v...
September 23, 2026 at 1:55 PM
Most exciting @threatinsight.proofpoint.com drop yet - in collaboration with NSA - and the product of @greg-l.bsky.social's blood, sweat, and tears. Research into two Russian actors throwing half-click exploits against mailservers. Part 1 on TA488 / Void Blizzard
www.proofpoint.com/us/blog/thre...
TA488 Targets Zimbra Mailservers with Half-Click Exploits | Proofpoint US
Proofpoint is releasing this report in coordination with NSA and FBI’s JSAC reporting about TA488/Void Blizzard, which can be found here. This is part 1 of a 2-part blog series Proofpoint is
www.proofpoint.com
July 23, 2026 at 2:12 PM
So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb?

Well...

We kinda lied

Day before the release, we found em throwing a half click against Outlook to install one of the coolest implants we’ve ever examined: OWAReaper

www.proofpoint.com/us/blog/thre...
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
www.proofpoint.com
July 29, 2026 at 9:12 AM
The excitement continues. @greg-l.bsky.social discovered Russia-aligned actor TA488 using another half-click exploit - this time in Outlook- leading to a new (very cool) browser-based implant, OWAReaper. Check out TA488 upping its game @threatinsight.proofpoint.com www.proofpoint.com/us/blog/thre...
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
www.proofpoint.com
July 29, 2026 at 9:10 AM
TA488 Targets Zimbra Mailservers with Half-Click Exploits
TA488 Targets Zimbra Mailservers with Half-Click Exploits | Proofpoint US
Proofpoint is releasing this report in coordination with NSA and FBI’s JSAC reporting about TA488/Void Blizzard, which can be found here. This is part 1 of a 2-part blog series Proofpoint is
www.proofpoint.com
July 23, 2026 at 5:34 PM
🚨 We are following up with additional observations of the TA488’s use of “half-click” exploits.

The group has initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA).

New blog: www.proofpoint.com/us/blog/thre...
July 29, 2026 at 8:34 PM
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit
www.proofpoint.com/us/blog/thre...
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
www.proofpoint.com
July 30, 2026 at 11:22 AM
TA488 May Have Exploited Outlook Web Access 0-Day Flaw Before Microsoft’s Emergency Patch
TA488 May Have Exploited Outlook Web Access 0-Day Flaw Before Microsoft’s Emergency Patch
TA488 has been linked to a new campaign that turns a routine Outlook Web Access email into a gateway for mailbox compromise. The operation abused a now-patched cross-site scripting flaw, tracked as CVE-2026-42897, and could run malicious code when a recipient opened a message in the webmail interface. The campaign targeted government bodies and organizations in telecommunications, finance, hospitality, and aerospace across the United States and Europe. Unlike common phishing attacks, the emails did not need a harmful attachment or a link, making them easier to overlook in a busy inbox. Analysts at  Proofpoint  identified the activity and named the browser-based implant OWAReaper. Proofpoint said in a report shared with Cyber Security News (CSN) that the group had improved the loading, persistence, and data theft capabilities used in its half-click attacks. The finding adds urgency to the wider response to the Outlook Web Access flaw. Earlier reporting on the  Microsoft Exchange server vulnerability  noted that the issue affected on-premises Exchange deployments and allowed attacker-controlled JavaScript to execute in an authenticated user’s browser session. TA488 May Have Exploited Outlook Web Access 0-Day Flaw TA488 began exploiting CVE-2026-42897 on July 22, 2026, according to the researchers. The campaign appeared just before public reporting tied the Russia-aligned group, also known as Void Blizzard and Laundry Bear, to earlier attacks against webmail platforms. The group used compromised accounts to distribute vague messages about supply chains, energy, tourism, public health, and market metrics. These subjects were designed to look ordinary enough for recipients to open and briefly review, rather than immediately report as suspicious. TA488 “Semiconductor Supply Chain” lure email from July 2026 (Source – Proofpoint) When a victim opened the email in Outlook Web Access, the Exchange server failed to safely handle parts of the message’s HTML content. That mistake let a hidden JavaScript loader reconstruct and run the OWAReaper payload directly inside the browser’s Outlook session. Researchers said the oldest infrastructure associated with the operation was created in March 2026, about two months before Microsoft issued its emergency response for the vulnerability. That timing means TA488 may have had access to the flaw as a zero-day before defenders could apply protections. Microsoft later issued permanent updates for affected supported Exchange versions, while CISA urged organizations to apply available updates and mitigations quickly. Organizations should also review their exposure to internet-facing Exchange systems, as outlined in the  CISA Exchange vulnerability warning . OWAReaper Builds Persistence OWAReaper operates entirely within the Outlook Web Access browser environment, leaving little or no traditional malware footprint on the endpoint. It can collect mailbox details, user settings, and saved browser credentials, then store an encrypted copy of itself in Outlook-related browser storage. JavaScript triggered by mishandled HTML sanitization (Source – Proofpoint) The implant also attempts to change mailbox folder permissions, potentially giving a low-privileged default account owner-level access to folders. This server-side access can survive password resets or a full rebuild of the victim’s computer unless administrators deliberately remove the altered permissions. TA488 OWAReaper infection chain (Source – Proofpoint) For command handling, OWAReaper can retrieve encrypted instructions from crafted GitHub commit messages or parse commands delivered through incoming email. It can also use HTTPS traffic routed through image delivery services, with DNS tunneling as a fallback method for sending stolen information. The most important response is to install the relevant Exchange updates and retain compensating protections where required. Security teams should revoke and audit Exchange Web Services tokens for affected add-ins, remove improper Default-user folder permissions, clear affected Outlook browser storage, and monitor or block connections to known command-and-control infrastructure. This campaign shows why email-borne attacks cannot be judged only by attachments and links. Security teams should investigate unexpected Outlook Web Access behavior, including suspicious scripts, unusual permission changes, and anomalous webmail sessions, while continuing to educate users about deceptive but seemingly harmless messages. The risks of weaponized mail remain clear in  recent phishing email campaigns , even when the delivery methods differ. Indicators of compromise (IoCs):- Type Indicator Description Domain asecdns[.]com OWAReaper command-and-control infrastructure Domain acocdn[.]com OWAReaper command-and-control infrastructure and HTTPS data relay Domain dnsrecursive[.]eu OWAReaper command-and-control infrastructure Domain tdndns[.]com OWAReaper command-and-control infrastructure SHA-256 6897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4 HTML message body containing the exploit and OWAReaper payload Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Building Resilience Against Phishing & Malware and  Analyze  it in a safe environment –  Power your SOC with ANY.RUN The post TA488 May Have Exploited Outlook Web Access 0-Day Flaw Before Microsoft’s Emergency Patch appeared first on Cyber Security News .
cybersecuritynews.com
July 30, 2026 at 6:13 AM
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit | Proofpoint US
Threat Research would like to thank the Proofpoint Cloudmark Authority team for their collaboration. Key Findings On 22 July 2026, one day prior to Proofpoint’s recent joint release
www.proofpoint.com
July 29, 2026 at 1:43 PM
📣🚨 Russian hackers exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.

Listen/Read: hackread.com/russian-hack...

#CyberSecurity #Zimbra #0day #Vulnerability #Russia #TA488
Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks
Follow us on all social media platforms at @HackRead - Thanks!
hackread.com
July 24, 2026 at 2:27 PM
TA488 exploits CVE-2026-42897 in Microsoft Exchange/OWA to deliver OWAReaper, gaining persistent access and stealing credentials from unpatched systems.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
July 31, 2026 at 2:42 PM
The exploitation of Outlook Web Access instances highlights the increased risk TA488 poses. See our blog for guidance on detection and remediation.

⚠️ Organizations should review and audit their Exchange permissions and revoke tokens for affected add-ins.
July 29, 2026 at 8:34 PM
Daily IT Security Digest — 2026-08-03
allowing long-term surveillance of corporate email inboxes. This is part of a broader campaign by TA488 to maintain persistent access to enterprise email systems.
Source: https://securityonline.bsky.social

## 8. Notable Data Breaches: Werth Wealth, Rectory
August 3, 2026 at 5:02 AM
Proofpoint just published a report on the campaign, which is notable for its use of view-only email exploitation, where the user just has to open the malware-laced message, not click any links or attachments: www.proofpoint.com/us/blog/thre...
TA488 Targets Zimbra Mailservers with Half-Click Exploits | Proofpoint US
Proofpoint is releasing this report in coordination with NSA and FBI’s JSAC reporting about TA488/Void Blizzard, which can be found here. This is part 1 of a 2-part blog series Proofpoint is
www.proofpoint.com
July 23, 2026 at 2:52 PM
Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover #cybersecurity #infosec
Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
A Russia-aligned threat group used a “half-click” exploit against Microsoft Exchange’s Outlook Web Access to install a browser-based backdoor when recipients opened specially crafted emails. The campaign began on July 22 and was conducted by TA488, which is also tracked as Void Blizzard and Laundry Bear, according to a report from the cybersecurity firm Proofpoint. The attacks targeted government organizations in the US and Europe, as well as companies in the telecommunications, financial, hospitality, and aerospace sectors. Proofpoint did not name the targeted organizations or say how many attacks resulted in successful compromises. The attackers exploited CVE-2026-42897, a cross-site scripting vulnerability caused by inadequate sanitization of HTML in email bodies. A recipient did not have to click a link or open an attachment. Viewing a crafted message in OWA allowed malicious JavaScript to execute inside the browser. Microsoft has previously said the flaw affects all update levels of Exchange Server 2016 and 2019, as well as Exchange Server Subscription Edition, while Exchange Online is not affected. The company disclosed the vulnerability on May 14 and issued an emergency mitigation before releasing a code fix in June. Microsoft later said customers who installed its July 2026 Exchange security update could remove the earlier mitigation. Proofpoint found that infrastructure associated with the campaign had been created in March, before Microsoft disclosed the vulnerability. The company said the timeline made it feasible that TA488 had used the flaw as a zero-day, although it did not confirm that such exploitation occurred. “TA488 used intentionally vague message lures with no call-to-action for the targeted user,” Proofpoint said. The messages resembled routine informational updates, including material on supply chains and market indicators. Opening one in OWA triggered OWAReaper, a previously undocumented JavaScript implant that runs inside the reading pane. OWAReaper removes the exploit code from the message stored on the Exchange server after execution, reducing the evidence visible to users and investigators. It can collect account information and attempt to capture credentials entered through browser autofill. If OWAReaper finds an Outlook add-in with ReadWriteMailbox permissions, it can use the add-in to obtain an OAuth token and grant owner-level access to Exchange’s built-in “Default” identity. This could allow an attacker controlling another authenticated account in the organization to continue accessing the victim’s mail folders. Because those permissions are stored on the Exchange server, changing the victim’s password or rebuilding the endpoint would not remove them. Mailbox persistence OWAReaper shifts incident response beyond the affected device because the attacker can establish persistence within Exchange itself, said Sakshi Grover, senior research manager for IDC Asia Pacific Cybersecurity Services. “The most important shift is where the attacker establishes persistence,” she said. Organizations should treat the compromise as a server-side identity incident rather than only an infected endpoint or stolen password, said Keith Prabhu, founder and CEO of Confidis. “The normal incident response is usually to reset the password, revoke tokens, and reimage the endpoint,” Prabhu said. “This may no longer be sufficient.” Detection blind spots Security tools focused on endpoint files or processes may fail to identify an implant operating inside the OWA browser session, Prabhu said. “Traditional email-security controls may also struggle because the delivery emails contain no obvious malicious attachment or conventional phishing link,” Grover said. Because OWAReaper operates within an authenticated OWA session and can abuse legitimate mailbox functions, individual events may not appear malicious when examined in isolation. Detecting the threat requires cross-layer correlation, Prabhu said. He recommended starting with users that opened suspicious OWA messages, then reviewing subsequent mailbox-permission changes, add-in activity, and OAuth events. Investigators should also examine browser-storage artifacts and related network metadata.
www.csoonline.com
August 3, 2026 at 2:58 PM
Russian-backed espionage used a Zimbra zero-day to read mailboxes for months, stealing emails, directories, passwords, and 2FA recovery codes from Western targets before the patch. #Zimbra #Russia #APT28
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-backed espionage group used CVE-2025-66376 in Zimbra's Classic UI to read Western mailboxes for months, stealing recent email, directories, saved passwords, and 2FA recovery codes. The campaign, tracked as TA488 and CL-STA-1114, used crafted HTML emails with the ZimReaper payload and targeted government, defense, transportation, financial, and US organizations...
www.hendryadrian.com
July 24, 2026 at 4:15 AM
📢 CVE-2026-42897 : TA488 exploite une XSS stockée dans Exchange OWA via l'implant OWAReaper

Cet article constitue une analyse technique approfondie de la vulnérabilité CVE-2026-42897 et de la campagne d'exploitation associée…

🟢 vérification factuelle haute
#ExchangeOWA #OWAReaper #Cyberveille
CVE-2026-42897 : TA488 exploite une XSS stockée dans Exchange OWA via l'implant OWAReaper
Cet article constitue une analyse technique approfondie de la vulnérabilité CVE-2026-42897 et de la campagne d'exploitation associée menée par le groupe TA488 (également connu sous les noms Void Blizzard et Laundry Bear), acteur étatique russe.
cyberveille.ch
September 4, 2026 at 4:30 PM
Proofpoint Blog 第59回 ロシア系攻撃グループTA488、ハーフクリックエクスプロイトでZimbraを侵害

ロシア系攻撃グループTA488がZimbraメールサーバーを標的に、Half-Click Exploitを悪用して認証情報とメールの窃取を行う攻撃を展開。ユーザーの操作を最小限に抑えた巧妙な手法で、攻撃の変遷や通信方法、インフラ特徴が確認されました。

#標的型攻撃 #情報セキュリティ
Proofpoint Blog 第59回 ロシア系攻撃グループTA488、ハーフクリックエクスプロイトでZimbraを侵害
ロシア系攻撃グループTA488がZimbraメールサーバーを標的に、Half-Click Exploitを悪用して認証情報とメールの窃取を行う攻撃を展開。ユーザーの操作を最小限に抑えた巧妙な手法で、攻撃の変遷や通信方法、インフラ特徴が確認されました。
scan.netsecurity.ne.jp
September 3, 2026 at 12:01 AM
「Zimbra」脆弱性にゼロデイ攻撃、露支援攻撃者が関与

Synacorが提供するコラボレーションツール「Zimbra Collaboration Suite(ZCS)」の脆弱性が、国家が関与すると見られる攻撃グループのゼロデイ攻撃で悪用されていたことがわかった。メールを表示するだけで、過去のメールが窃取される状態だった。

...

ロシア政府の支援を受けていると見られ、「Void Blizzard」「CL-STA-1114」「TA488(旧UNK_PitStop)」などとしても追跡されている攻撃グループ「LAUNDRY BEAR」が、当時明らかとなっていなかった脆弱性「CVE-20...
【セキュリティ ニュース】「Zimbra」脆弱性にゼロデイ攻撃、露支援攻撃者が関与(1ページ目 / 全2ページ):Security NEXT
Synacorが提供するコラボレーションツール「Zimbra Collaboration Suite(ZCS)」の脆弱性が、国家が関与すると見られる攻撃グループのゼロデイ攻撃で悪用されていたことがわかった。メールを表示するだけで、過去のメールが窃取される状態だった。 :Security NEXT
www.security-next.com
August 25, 2026 at 1:38 PM
Cyber Threat Exploits Outlook Web Access Flaw to Deploy OWReaper Mail Implant

Discover how an advanced threat actor exploits an Outlook Web Access flaw to deploy the OWReaper mail implant to compromise enterprise communications.
Read the full threat analysis: www.ampcuscyber.com/shadowopsint...
TA488 OWAReaper Outlook Malware Attack Explained
Learn how TA488 uses OWAReaper to exploit Outlook Web Access, steal credentials, and maintain persistent email access across organizations.
www.ampcuscyber.com
August 19, 2026 at 12:17 PM
Russian Hackers Use Exchange Zero-Day in Email Attacks #DNSAttack #DriftOAuthtokenhack #emailsecurity
Russian Hackers Use Exchange Zero-Day in Email Attacks
  Russia-aligned cyberespionage group Laundry Bear, also tracked as Void Blizzard and TA488, is exploiting a Microsoft Exchange Outlook Web Access (OWA) vulnerability to deploy a browser-based backdoor capable of maintaining access to victims' mailboxes even after credentials are changed or systems are reimaged. Email security firm Proofpoint said it observed the campaign targeting government organizations in the US and Europe, as well as telecommunications, financial, hospitality and aerospace organizations. The activity uses OWAReaper, a sophisticated backdoor delivered through malicious emails exploiting CVE-2026-42897. CVE-2026-42897 is a cross-site scripting vulnerability caused by inadequate HTML sanitization in OWA. A specially crafted email can contain malicious JavaScript that executes when the recipient opens the message in OWA. Proofpoint calls the technique a "half-click" exploit because opening the email can be enough to trigger the attack, without requiring the victim to click a link or open an attachment. Microsoft disclosed the vulnerability on May 14, 2026, and confirmed active exploitation. Proofpoint found that infrastructure associated with the campaign had been established as early as March, nearly two months before Microsoft's disclosure, suggesting TA488 may have exploited the vulnerability as a zero-day. The group used ordinary-looking subjects concerning supply chains, research updates, tourism, gas markets and other industry-related information, making the messages less likely to be treated as malicious. The emails contained JavaScript loaders and Base64-encoded payload fragments hidden within URLs associated with social-media-style icons. Once triggered, the code assembled and executed the OWAReaper payload. OWAReaper operates entirely within the OWA reading pane. It can collect the victim's email address, username and Outlook configuration, while also attempting to capture credentials by creating invisible DOM elements that allow the browser's autofill mechanism to populate usernames and passwords. The backdoor's most concerning capability is its persistence. It searches for Outlook add-ins with "ReadWriteMailbox" permissions and can use the "GetClientAccessToken" operation to obtain OAuth tokens. It then abuses Exchange's "UpdateFolder" operation to grant Owner-level permissions to the "Default" user across the victim's mail folders. Because these permissions are stored server-side, changing the victim's password or reinstalling the compromised computer does not necessarily remove the attacker's access. OWAReaper also enables browser caching and places a malicious iframe into messages stored in OWA's offline IndexedDB database, allowing the payload to execute again when a poisoned message is opened from the cache. The malware uses multiple channels for command and control. It periodically searches GitHub commit messages for encrypted commands containing the victim's email address and can also receive commands through specially formatted emails stored in OWA's cache. For data theft, OWAReaper primarily uses HTTPS with encrypted URI paths that can be routed through image CDN services. It also has a direct-server fallback and a DNS-based exfiltration mechanism that encrypts and Base32-encodes stolen data before transmitting it through DNS queries. Proofpoint linked OWAReaper to TA488 based on behavioral similarities with ZimReaper, malware previously used by the group against Zimbra email servers. In that campaign, TA488 exploited another XSS flaw, CVE-2025-66376, to steal emails, passwords, application passcodes and two-factor authentication codes. The latest campaign therefore represents an evolution of the group's "half-click" approach, shifting from compromising individual webmail sessions toward establishing persistent access within the victim's mailbox environment. Microsoft has since released security updates addressing CVE-2026-42897. The July 2026 Exchange Server update states that the code fix is available, while organizations that previously applied Microsoft's mitigation must follow Microsoft's guidance to remove it after installing the update. The vulnerability affects on-premises Exchange Server deployments, while Exchange Online is not affected. Proofpoint has published indicators of compromise for the campaign, including malicious domains and the HTML message body containing the exploit and OWAReaper payload. Organizations using affected on-premises Exchange deployments should therefore investigate not only compromised endpoints, but also mailbox permissions, OAuth tokens and OWA browser storage when responding to suspected exploitation.
dlvr.it
August 15, 2026 at 4:24 PM