Russian-aligned APT Laundry Bear (TA488) is exploiting CVE-2026-42897, a high-severity Cross-Site Scripting (XSS) vulnerability in Microsoft Outlook Web Access (OWA), to achieve persistent mailbox access. The attack utilizes a "half-click" vector, where merely viewing a malicious email in the OWA reading pane triggers the execution of the "OWAReaper" JavaScript implant. The adversary achieves server-side persistence by abusing Outlook add-ins with ReadWriteMailbox permissions to harvest OAuth tokens. This mechanism allows attackers to maintain access even after password resets or endpoint re-imaging. Affected environments include on-premises Exchange Server 2016, 2019, and Subscription Edition, while Exchange Online remains unaffected.
-
Incident & Threat Actor Overview
- Actor Profile: Identified as Laundry Bear (also known as TA488, Void Blizzard, or CL-STA-1114).
- Intelligence Context: Command-and-control (C2) infrastructure was observed being staged as early as March 2026.
- Strategic Intent: Sophisticated espionage targeting high-value intelligence and communication streams.
-
Vulnerability Mechanics: CVE-2026-42897
- Vulnerability Type: Cross-Site Scripting (XSS) with a CVSS score of 8.1.
- Root Cause: Inadequate HTML sanitization of email bodies within the OWA interface.
- Exploitation Vector: "Half-click" execution, requiring zero user interaction beyond the rendering of the email in the OWA reading pane.
- Affected Software: Microsoft Exchange Server 2016, 2019, and Subscription Edition.
-
Malware Analysis: OWAReaper Implant
- Payload Type: JavaScript-based browser implant executed within authenticated OWA sessions.
- Core Capabilities: Credential harvesting via browser autofill and collection of sensitive account metadata.
- Anti-Forensic Measures: Employs automated post-execution code removal to erase traces of the exploit.
-
Persistence & Identity Abuse
- Primary Method: Exploitation of Outlook add-ins possessing
ReadWriteMailboxpermissions. - Persistence Mechanism: Theft of OAuth tokens to establish long-term, server-side identity access.
- Defensive Bypass: Maintains access through standard remediation efforts, including endpoint re-imaging and password rotations.
- Primary Method: Exploitation of Outlook add-ins possessing
-
Impact & Defensive Requirements
- Targeted Sectors: U.S. and European Government, Telecommunications, Aerospace, and Financial Services.
- Detection Complexity: High; requires correlation of mailbox permissions, add-in activity, and anomalous OAuth events.
- Remediation Focus: Requires identity-layer auditing and permission revocation rather than traditional endpoint cleanup.
Related posts
- TechNadu — TA488 Half-Click Exploit Moves to Outlook Web Access Flaw, Deploys Persistent OWAReaper Backdoor
- blackhatnews.tokyo
- blackswan-cybersecurity.com — THREAT ADVISORY Russian APT “Laundry Bear” Exploiting OWA XSS for Persistent Mailbox Access August 5, 2026
- Malware News — Russian hackers can steal government emails without victims clicking a link, cyber agencies warn
- CISA All Advisories — Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite
- computerweekly.com — Laundry Bear pivots to new exploit days after Zimbra alert
- feeds.feedburner.com — Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
- csoonline.com — Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
- Proofpoint
- Infosecurity-magazine
- Connect
- Compudent