Imagine: Proofpoint
At a glance
| Actor | TA488 (Void Blizzard / Laundry Bear), Russia-aligned |
| Activity | Half-click XSS exploit of Outlook Web Access; browser implant |
| Targets | US and European government; telecom, finance, hospitality, aerospace |
| Scale | Broad campaign from 22 July 2026; infrastructure built March 2026 |
| Status | Attributed by Proofpoint; joint NSA/FBI reporting; no arrests |
| Source | Proofpoint Threat Research |
TL;DR
Proofpoint tracked a new half-click exploit campaign by the Russia-aligned group TA488. The attackers abused an Outlook Web Access flaw, so simply opening an email ran their code. That code installs OWAReaper, a browser implant that survives device reimaging.
What happened
On 22 July 2026, TA488 launched a wave of attacks against Outlook Web Access, or OWA. The group abused CVE-2026-42897, a cross-site scripting flaw in Microsoft Exchange webmail. It was another half-click exploit, a signature move for this actor.
The campaign hit government bodies across the US and Europe. It also reached telecom, finance, hospitality, and aerospace targets. That breadth was unusual for TA488, and may have been meant to blend in with spam.
Why “half-click” matters
Most email attacks need a click on a link or file. This one did not. As Proofpoint describes it, this is an attack “where opening the email is enough to trigger compromise.”
The lures were dull on purpose. Subjects covered supply chains, gas markets, and tourism metrics. No links or attachments appeared, so users were likely to skim, shrug, and never report the message.
How the exploit works
OWA failed to sanitize the HTML in the message body. When a target opened the email, the server ran attacker JavaScript in the browser. That script quietly assembled a hidden payload stored inside the message. Then it launched OWAReaper.
The OWAReaper implant
OWAReaper runs entirely inside the OWA reading pane. First, it rewrites the malicious email to erase the exploit. Next, it harvests the victim’s OWA credentials by abusing the browser’s autofill.
Persistence is the standout feature. The implant hides an encrypted copy of itself inside a legitimate OWA settings key. So every time the victim opens OWA, the malware runs again.
OWAReaper also grants itself broad mailbox permissions on the Exchange server. Proofpoint warns that “full re-imaging of the targeted user’s device will not evict the actor.” Removal requires cleanup on the server itself.
Command, control, and theft
The implant takes orders through two channels. It reads commands from crafted GitHub commit messages, or from inbound attacker emails. Both paths use encryption to hide the instructions.
For theft, OWAReaper favors encrypted HTTPS traffic disguised as image requests through legitimate CDNs. If that fails, it hides data inside DNS queries to an actor-controlled domain. This article withholds live indicators.
Who is behind it
Proofpoint attributes the campaign to TA488, also known as Void Blizzard and Laundry Bear. The assessment rests on tradecraft overlaps with the group’s earlier ZimReaper malware. TA488 is a Russia-aligned espionage actor.
The timeline raises the stakes. The earliest infrastructure appeared in March 2026, two months before Microsoft’s out-of-band fix. So TA488 may have used the flaw as a zero-day, though that is not confirmed.
How to stay protected
Patch Exchange now if you run OWA on-premises. Microsoft rated CVE-2026-42897 at 8.1 and shipped emergency mitigations during active exploitation.
Proofpoint also urges defenders to revoke suspect add-in tokens and audit mailbox folder permissions. Teams should clear OWA’s offline cache and the abused settings key on affected endpoints. For the full technical breakdown, read the Proofpoint analysis.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.