The bottom line: Laundry Bear exploits a zero-day vulnerability in Exchange OWA to distribute the OWAReaper backdoor for persistent mailbox access.
The Russian hacker group Laundry Bear (also known as Void Blizzard) is exploiting a zero-day vulnerability in Microsoft Exchange Outlook Web Access to distribute a backdoor called OWAReaper. This enables long-term, unauthorized access to mailboxes of target organizations.
The Russian, state-backed hacker group Laundry Bear, also known by the name Void Blizzard, is exploiting a vulnerability in Microsoft Exchange Outlook Web Access (OWA) in targeted email campaigns. Through this vulnerability, a backdoor named OWAReaper is distributed, which allows attackers to gain long-term access to mailboxes of target organizations.
For CISOs, this campaign represents a significant risk: the OWAReaper backdoor not only enables attackers to access sensitive emails immediately after compromise, but also leaves persistent back doors that are difficult to detect. This is typical of state-sponsored operations aimed at long-term espionage.
Affected organizations should monitor their Exchange environments for suspicious OWA access, prioritize patches for this zero-day vulnerability once they become available, and review their email security solutions. Special attention should be paid to suspicious forwarding rules, logon activities, and unknown mobile clients, which can be characteristic indicators of this type of backdoor access.
Source: www.bleepingcomputer.com · Published 30 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.