Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
Proofpoint says the Russian-linked group used attacker-controlled JavaScript to keep access to compromised mailboxes and targeted government and industry victims.
- The Russian espionage group TA488, also known as 'Laundry Bear,' is exploiting CVE-2026-42897, a cross-site scripting flaw in Microsoft Outlook Web Access, to gain persistent mailbox access without requiring user clicks or downloads.
- Unlike conventional phishing attacks, the group deploys a browser implant called OWAReaper that resides entirely inside Outlook Web Access, allowing it to survive password changes and full device rebuilds because the foothold persists on the server rather than the endpoint.
- Proofpoint reports TA488 targeted government organizations in the US and Europe, along with telecommunications and aerospace firms, using infrastructure dating back to March—two months before Microsoft's May mitigation advisory.
- Security researchers believe the group likely exploited the flaw as a zero-day vulnerability, suggesting the campaign was underway well before defenders knew a vulnerability existed, signaling a significant leap in TA488's technical capability.
- The activity forms part of a broader espionage campaign; TA488 exploited Zimbra Collaboration Suite using similar tactics just days earlier, though Microsoft notes Exchange Online customers remain unaffected by this specific vulnerability.
15 Articles
15 Articles
Russian state hackers deploy persistent Exchange backdoor that survives disk reimaging
Security researchers at Proofpoint published new findings on July 29, 2026, detailing a fresh campaign by TA488, a Russian hacking group also known as Void Blizzard and Laundry Bear. The report credits researchers Greg Lesnewich, Stuart Del Caliz, Nick Attfield, Konstantin Klinger, Saher Naumaan and Mark Kelly, along with the Proofpoint Threat Research Team. The group is exploiting a vulnerability in Microsoft Exchange Server that compromises a …
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
Russian state hackers are using a maximum-severity vulnerability in Microsoft Outlook’s Exchange Server to backdoor unpatched machines and steal credentials and other confidential information from them, security researchers said Thursday. The attacks are coming from TA488, a tracking name for a group working on behalf of the Kremlin, Proofpoint researchers said Thursday. Proofpoint and the National Security Agency jointly warned last week that t…
Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
A Russia-aligned threat group used a “half-click” exploit against Microsoft Exchange’s Outlook Web Access to install a browser-based backdoor when recipients opened specially crafted emails. The campaign began on July 22 and was conducted by TA488, which is also tracked as Void Blizzard and Laundry Bear, according to a report from the cybersecurity firm Proofpoint. The attacks targeted government organizations in the US and Europe, as well as co…
Russian spies take their half-click email attack from Zimbra to Outlook
The Russian espionage crew that turned simply reading an email into a security risk has expanded beyond Zimbra, with Proofpoint saying it's now pulling the same half-click trick against Microsoft Outlook Web Access. Proofpoint says the cyber group it tracks as TA488, or "Laundry Bear," began exploiting CVE-2026-42897, a cross-site scripting flaw in the Outlook Web Access (OWA) component of on-premises Exchange Server, a day before researchers an…
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper.
Wednesday, April 15, 2026. The engineers of the National Secure Titles Agency (ANTS, the platform used to file applications for identity cards, passports or grey cards) detect with... The article Cybersecurity: how the state became the preferred target of hackers appeared first on Current Values.
Coverage Details
Bias Distribution
- 83% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium









