Skip to content

Russian Hackers Exploit Exchange OWA Zero-Day for Persistent Mailbox Access

In a nutshell: An undisclosed Exchange OWA vulnerability is being exploited by Laundry Bear to deploy persistent backdoors in enterprise mailboxes.

The Russian state-backed hacker group Laundry Bear (also known as Void Blizzard) is abusing an unpatched vulnerability in Microsoft Exchange Outlook Web Access to deliver the OWAReaper backdoor and gain long-term access to mailboxes.

The Russian state-sponsored hacker group Laundry Bear (alias Void Blizzard) is using a previously unknown vulnerability in Microsoft Exchange Outlook Web Access (OWA) in email campaigns. Through this vulnerability, the specialized OWAReaper backdoor is deployed, giving the attacker persistent and seemingly legitimate access to enterprise mailboxes.

For CISOs, this campaign is critical because it combines multiple escalation factors: First, it is a zero-day vulnerability with no patch yet available. Second, OWAReaper exploits the OWA interface itself as an attack vector — a service that typically runs with elevated privileges and is necessary for legitimate email functions. Third, the backdoor allows the attacker to log into the mailbox like a normal user, which makes detection through standard anomaly detection difficult.

As immediate measures, organizations should monitor their Exchange systems for suspicious OWA authentications, particularly login patterns outside of known business hours or from unexpected locations. Enabling multi-factor authentication at the mailbox level can limit misuse of already compromised accounts. Until Microsoft provides an official patch, network segmentation of Exchange systems and restricting OWA access to trusted IP addresses are recommended.


Source: www.bleepingcomputer.com · Published 30 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification through Lumi News Pipeline v1.7.3.

Share on: