The point: Laundry Bear exploits a half-click vulnerability in Outlook to compromise email inboxes of European and North American targets without requiring conscious user action.
The Russian hacker group Laundry Bear has been conducting attack operations against Outlook users for months, where simply opening an email is sufficient for compromise. The attacks also target European entities.
Laundry Bear employs a so-called half-click exploit to gain access to email inboxes. The attack method requires minimal interaction from the victim — merely opening a prepared message — to enable malware execution or further access.
The operations have been running for several months, indicating an established campaign. Target groups are located not only in North America but also in European organizations. The use of this technique points to a deliberately conducted spear-phishing operation in which highly specific emails are sent to targeted objects.
For CISOs, it is relevant that the half-click method partially circumvents classical user awareness training — since minimal or no conscious user action is required. Outlook environments should be monitored for suspicious email headers, unexpected script execution, and post-open callbacks. Microsoft security updates and email filter rules to block suspicious file attachments or embedded objects should be deployed as a priority.
Source: www.golem.de · Published July 30, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.