TA488, a group known for its cyber activities, has been connected to a new campaign that exploits a vulnerability in Outlook Web Access. This campaign uses a now-fixed cross-site scripting flaw, identified as CVE-2026-42897, allowing malicious code execution when a user opens an email via the web interface.
Targeted Campaigns Across Sectors
The operation has primarily focused on governmental bodies and sectors like telecommunications, finance, hospitality, and aerospace in the United States and Europe. Unlike typical phishing attempts, these emails do not carry harmful attachments or links, making them more likely to evade detection in crowded inboxes.
Researchers at Proofpoint have uncovered this activity and named the browser-based implant OWAReaper. According to a report shared with Cyber Security News, the group has enhanced the malware’s loading, persistence, and data extraction abilities, elevating the threat level significantly.
Implications of the Vulnerability
The urgency to address the Outlook Web Access flaw has increased. Previous reports highlighted that the vulnerability impacted on-premises Microsoft Exchange servers, enabling attackers to execute JavaScript in authenticated users’ browsers. TA488 began exploiting this flaw on July 22, 2026, prior to its public disclosure.
The group, also known by the aliases Void Blizzard and Laundry Bear, distributed emails with generic topics like supply chains and market metrics, designed to appear ordinary and bypass suspicion. This subtlety in approach enabled the execution of the OWAReaper payload when victims opened the emails.
Security Measures and Future Outlook
Microsoft has since released permanent updates for affected Exchange versions, and CISA has urged organizations to apply these updates promptly. It’s crucial for entities to evaluate their exposure to internet-facing Exchange systems and implement recommended security measures.
OWAReaper operates within the Outlook Web Access environment, leaving minimal traces on endpoints. It gathers mailbox data and stores an encrypted version of itself in browser storage. It also attempts to modify mailbox permissions, potentially granting higher access levels than intended.
To combat these threats, organizations should ensure Exchange updates are installed, audit Exchange Web Services tokens, and monitor for any unusual Outlook Web Access activities. As email-based threats continue to evolve, educating users on recognizing deceptive emails remains a key defense strategy.
In conclusion, the risk posed by email-borne threats is evident, and organizations must remain vigilant in their cybersecurity efforts to mitigate such vulnerabilities.
