Russian threat actors have been identified exploiting a flaw in Microsoft Outlook Web Access (OWA) to target various sectors in the U.S. and Europe. This development follows their previous use of a Zimbra vulnerability. The attackers focus on government, telecommunications, financial, hospitality, and aerospace entities.
Exploiting CVE-2026-42897
The cyber campaign, which began on July 22, 2026, leverages CVE-2026-42897, a cross-site scripting vulnerability in OWA with a CVSS score of 8.1. Microsoft had identified this flaw as being exploited since May 2026. Proofpoint attributes the attacks to a group called Laundry Bear, also known as TA488, which previously exploited a Zimbra vulnerability.
In these attacks, adversaries sent emails from compromised accounts, leading to the execution of a JavaScript payload, ZimReaper, that extracted data from the victim’s email. The group has improved its tactics, employing more sophisticated loading methods and malware tools.
Techniques and Tactics
The attackers use compromised accounts to send phishing emails without requiring recipient interaction. These emails mimic legitimate communications, avoiding any URLs or attachments to reduce suspicion. Once opened, they trigger the execution of malicious code exploiting CVE-2026-42897.
The malicious JavaScript uses an onload event handler to activate upon opening. It assembles and executes a script embedded in the message, leading to the deployment of a browser-based implant, OWAReaper, which maintains persistent access to the compromised accounts.
Persistent Threats and Responses
OWAReaper is an evolved form of ZimReaper, designed to operate within the OWA reading pane. It manipulates Outlook APIs to rewrite emails on the Exchange server, removes exploit traces, and uses sophisticated methods to maintain access, even after credential changes or system re-imaging.
The malware also utilizes GitHub and attacker-sent emails as command-and-control channels. It checks for messages with specific structures to execute commands discreetly, often using encrypted paths for data exfiltration.
Proofpoint’s findings suggest that the infrastructure for these attacks was set up months before the vulnerability was publicly disclosed, indicating possible zero-day exploitation. The group’s activity paused from February to July 2026, but the new wave highlights their continued focus on intelligence gathering across various sectors.
The persistent nature of these attacks underscores the need for organizations to enhance their security measures and remain vigilant against evolving cyber threats.
